2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23264 | HIGH | 7.8 | 0.3% | Jun 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i... |
| CVE-2025-6569 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu... |
| CVE-2025-6568 | HIGH | 8.8 | 0.8% | Jun 24, 2025 | A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown... |
| CVE-2025-6567 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss... |
| CVE-2025-36537 | HIGH | 7 | 0.2% | Jun 24, 2025 | Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and ... |
| CVE-2025-32978 | HIGH | 7.5 | 0.9% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-32977 | CRITICAL | 9.6 | 0.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-32976 | HIGH | 8.8 | 0.8% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-32975 | CRITICAL | 10 | 2.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-6032 | HIGH | 8.3 | 0.5% | Jun 24, 2025 | A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM ... |
| CVE-2025-5318 | MEDIUM | 5.4 | 1.5% | Jun 24, 2025 | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_... |
| CVE-2025-27828 | HIGH | 7.1 | 0.4% | Jun 24, 2025 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.... |
| CVE-2025-27827 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthen... |
| CVE-2025-6566 | HIGH | 7.5 | 0.7% | Jun 24, 2025 | A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-6565 | HIGH | 8.8 | 0.7% | Jun 24, 2025 | A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function ht... |
| CVE-2025-6436 | HIGH | 8.1 | 2.9% | Jun 24, 2025 | Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-6435 | HIGH | 8.1 | 0.4% | Jun 24, 2025 | If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not hav... |
| CVE-2025-6434 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking ... |
| CVE-2025-6433 | CRITICAL | 9.8 | 0.2% | Jun 24, 2025 | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a... |
| CVE-2025-6432 | HIGH | 8.6 | 0.3% | Jun 24, 2025 | When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was inval... |
| CVE-2025-6431 | MEDIUM | 6.5 | 0.2% | Jun 24, 2025 | When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing... |
| CVE-2025-6430 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was ... |
| CVE-2025-6429 | MEDIUM | 6.5 | 0.3% | Jun 24, 2025 | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in... |
| CVE-2025-6428 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc... |
| CVE-2025-6427 | CRITICAL | 9.1 | 0.3% | Jun 24, 2025 | An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now