2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23170 | MEDIUM | 6.7 | 0.6% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the ... |
| CVE-2025-23169 | MEDIUM | 6.1 | 0.3% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, foote... |
| CVE-2025-23168 | HIGH | 8.8 | 0.3% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OT... |
| CVE-2025-23121 | HIGH | 8.8 | 11.6% | Jun 19, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
| CVE-2025-49591 | CRITICAL | 9.1 | 0.4% | Jun 18, 2025 | CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad... |
| CVE-2025-49590 | MEDIUM | 6.1 | 0.3% | Jun 18, 2025 | CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javasc... |
| CVE-2025-26199 | CRITICAL | 9.8 | 0.5% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm... |
| CVE-2025-6192 | HIGH | 8.8 | 0.4% | Jun 18, 2025 | Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap... |
| CVE-2025-6191 | HIGH | 8.8 | 8.8% | Jun 18, 2025 | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of ... |
| CVE-2025-29646 | HIGH | 7.1 | 0.3% | Jun 18, 2025 | An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se... |
| CVE-2025-26198 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The... |
| CVE-2025-20260 | CRITICAL | 9.8 | 1.5% | Jun 18, 2025 | A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe... |
| CVE-2025-20271 | HIGH | 8.6 | 0.5% | Jun 18, 2025 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2025-20234 | HIGH | 7.5 | 0.7% | Jun 18, 2025 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to c... |
| CVE-2025-1349 | MEDIUM | 4.8 | 0.2% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulne... |
| CVE-2025-1348 | MEDIUM | 4 | 0.1% | Jun 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allo... |
| CVE-2025-4821 | HIGH | 7.5 | 0.7% | Jun 18, 2025 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to... |
| CVE-2025-4820 | MEDIUM | 5.3 | 0.7% | Jun 18, 2025 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to... |
| CVE-2025-44952 | HIGH | 7.8 | 0.2% | Jun 18, 2025 | A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 an... |
| CVE-2025-44951 | HIGH | 7.1 | 0.2% | Jun 18, 2025 | A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and e... |
| CVE-2025-36049 | HIGH | 8.8 | 0.5% | Jun 18, 2025 | IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE)... |
| CVE-2025-36048 | HIGH | 7.2 | 0.4% | Jun 18, 2025 | IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privilege... |
| CVE-2025-6240 | MEDIUM | 4.9 | 0.3% | Jun 18, 2025 | Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authenti... |
| CVE-2025-46109 | HIGH | 8.8 | 0.4% | Jun 18, 2025 | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information vi... |
| CVE-2025-45786 | HIGH | 8.1 | 0.3% | Jun 18, 2025 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now