2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28382 | HIGH | 7.5 | 0.9% | Jun 13, 2025 | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers... |
| CVE-2025-28381 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables... |
| CVE-2025-28380 | MEDIUM | 6.1 | 0.3% | Jun 13, 2025 | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scri... |
| CVE-2025-46096 | MEDIUM | 6.1 | 0.5% | Jun 13, 2025 | Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-lu... |
| CVE-2025-46060 | CRITICAL | 9.8 | 1.0% | Jun 13, 2025 | Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-45988 | CRITICAL | 9.8 | 9.7% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45987 | CRITICAL | 9.8 | 2.3% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45986 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45985 | CRITICAL | 9.8 | 7.1% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45984 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT... |
| CVE-2025-49468 | HIGH | 8.6 | 0.4% | Jun 13, 2025 | A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability al... |
| CVE-2025-29902 | CRITICAL | 10 | 1.0% | Jun 13, 2025 | Remote code execution that allows unauthorized users to execute arbitrary code on the server machine. |
| CVE-2025-48825 | LOW | 2.5 | 0.1% | Jun 13, 2025 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al... |
| CVE-2025-46783 | CRITICAL | 9.8 | 0.8% | Jun 13, 2025 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability... |
| CVE-2025-36506 | MEDIUM | 6.9 | 0.4% | Jun 13, 2025 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an ... |
| CVE-2025-6012 | MEDIUM | 5.5 | 0.2% | Jun 13, 2025 | The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2025-39240 | HIGH | 7.2 | 1.1% | Jun 13, 2025 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input ... |
| CVE-2025-5923 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in... |
| CVE-2025-22242 | MEDIUM | 5.6 | 0.1% | Jun 13, 2025 | Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method w... |
| CVE-2025-22241 | MEDIUM | 5.6 | 0.2% | Jun 13, 2025 | File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated inpu... |
| CVE-2025-22240 | MEDIUM | 6.3 | 0.1% | Jun 13, 2025 | Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.pa... |
| CVE-2025-22239 | HIGH | 8.1 | 0.2% | Jun 13, 2025 | Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se... |
| CVE-2025-22238 | MEDIUM | 4.2 | 0.3% | Jun 13, 2025 | Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traver... |
| CVE-2025-22237 | MEDIUM | 6.7 | 0.2% | Jun 13, 2025 | An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git ur... |
| CVE-2025-22236 | HIGH | 8.1 | 0.1% | Jun 13, 2025 | Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now