2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6557 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh... |
| CVE-2025-6556 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co... |
| CVE-2025-6555 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea... |
| CVE-2025-53021 | MEDIUM | 4.2 | 0.3% | Jun 24, 2025 | A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions ... |
| CVE-2025-52888 | HIGH | 7.5 | 0.3% | Jun 24, 2025 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entit... |
| CVE-2025-52882 | HIGH | 8.8 | 0.3% | Jun 24, 2025 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium)... |
| CVE-2025-52880 | MEDIUM | 4.2 | 0.3% | Jun 24, 2025 | Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be... |
| CVE-2025-52571 | CRITICAL | 9.6 | 0.3% | Jun 24, 2025 | Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It ... |
| CVE-2025-52471 | CRITICAL | 9.8 | 0.7% | Jun 24, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide... |
| CVE-2025-49853 | CRITICAL | 9.3 | 0.4% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke... |
| CVE-2025-49852 | HIGH | 8.7 | 0.4% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability... |
| CVE-2025-49851 | CRITICAL | 9.8 | 0.5% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability wh... |
| CVE-2025-5087 | MEDIUM | 6 | 0.2% | Jun 24, 2025 | Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capa... |
| CVE-2025-2566 | CRITICAL | 9.3 | 0.5% | Jun 24, 2025 | Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated atta... |
| CVE-2025-53073 | MEDIUM | 4.2 | 0.2% | Jun 24, 2025 | In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize... |
| CVE-2025-49147 | MEDIUM | 5.3 | 0.3% | Jun 24, 2025 | Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a... |
| CVE-2025-23260 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t... |
| CVE-2025-4378 | CRITICAL | 10 | 0.3% | Jun 24, 2025 | Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A... |
| CVE-2025-6570 | HIGH | 8.8 | 0.4% | Jun 24, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected... |
| CVE-2025-50699 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q... |
| CVE-2025-50695 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de... |
| CVE-2025-50693 | MEDIUM | 6.5 | 0.3% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ... |
| CVE-2025-4383 | CRITICAL | 9.3 | 0.3% | Jun 24, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm.... |
| CVE-2025-44531 | HIGH | 7.5 | 0.4% | Jun 24, 2025 | An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a... |
| CVE-2025-23265 | HIGH | 7.8 | 0.3% | Jun 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now