2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6426 | HIGH | 8.8 | 0.2% | Jun 24, 2025 | The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec... |
| CVE-2025-6425 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified ... |
| CVE-2025-6424 | CRITICAL | 9.8 | 3.1% | Jun 24, 2025 | A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140... |
| CVE-2025-39205 | HIGH | 7.1 | 0.2% | Jun 24, 2025 | A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a... |
| CVE-2025-39204 | HIGH | 8.5 | 0.3% | Jun 24, 2025 | A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface... |
| CVE-2025-39203 | HIGH | 7.1 | 0.2% | Jun 24, 2025 | A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from ... |
| CVE-2025-39202 | HIGH | 8.1 | 0.2% | Jun 24, 2025 | A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with lo... |
| CVE-2025-39201 | MEDIUM | 6.1 | 0.1% | Jun 24, 2025 | A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to... |
| CVE-2025-2403 | HIGH | 8.7 | 0.3% | Jun 24, 2025 | A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in ... |
| CVE-2025-1718 | HIGH | 7.1 | 0.3% | Jun 24, 2025 | An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device... |
| CVE-2025-6206 | HIGH | 7.5 | 0.4% | Jun 24, 2025 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is... |
| CVE-2025-3092 | HIGH | 7.5 | 0.4% | Jun 24, 2025 | An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint. |
| CVE-2025-3091 | HIGH | 7.5 | 0.3% | Jun 24, 2025 | An low privileged remote attacker in possession of the second factor for another user can login as that user without kno... |
| CVE-2025-5258 | MEDIUM | 6.4 | 0.2% | Jun 24, 2025 | The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter... |
| CVE-2025-50213 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ... |
| CVE-2025-3090 | HIGH | 8.2 | 0.4% | Jun 24, 2025 | An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authent... |
| CVE-2025-2962 | HIGH | 7.5 | 0.5% | Jun 24, 2025 | A denial-of-service issue in the dns implemenation could cause an infinite loop. |
| CVE-2025-48890 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-43879 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-43877 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be... |
| CVE-2025-41427 | HIGH | 8.8 | 1.0% | Jun 24, 2025 | WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command... |
| CVE-2025-36519 | MEDIUM | 5.3 | 0.3% | Jun 24, 2025 | Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B... |
| CVE-2025-52570 | LOW | 1.7 | 0.3% | Jun 24, 2025 | Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. I... |
| CVE-2025-52568 | HIGH | 8.8 | 0.4% | Jun 24, 2025 | NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issue... |
| CVE-2025-52566 | HIGH | 8.8 | 0.3% | Jun 24, 2025 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now