2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46035 | HIGH | 7.5 | 0.6% | Jun 12, 2025 | Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the o... |
| CVE-2025-36573 | MEDIUM | 5.5 | 0.1% | Jun 12, 2025 | Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul... |
| CVE-2025-29744 | MEDIUM | 5.4 | 0.2% | Jun 12, 2025 | pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers. |
| CVE-2025-49200 | HIGH | 7.5 | 0.4% | Jun 12, 2025 | The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downl... |
| CVE-2025-49199 | CRITICAL | 9.8 | 0.3% | Jun 12, 2025 | The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP... |
| CVE-2025-49198 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of... |
| CVE-2025-49197 | HIGH | 7.5 | 0.2% | Jun 12, 2025 | The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access ... |
| CVE-2025-49196 | CRITICAL | 9.1 | 0.2% | Jun 12, 2025 | A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati... |
| CVE-2025-49195 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user pas... |
| CVE-2025-49194 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an a... |
| CVE-2025-49193 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The application fails to implement several security headers. These headers help increase the overall security level of t... |
| CVE-2025-49192 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta... |
| CVE-2025-49191 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded... |
| CVE-2025-49190 | MEDIUM | 5.8 | 0.3% | Jun 12, 2025 | The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal req... |
| CVE-2025-49189 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via cl... |
| CVE-2025-49188 | HIGH | 7.5 | 0.4% | Jun 12, 2025 | The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gat... |
| CVE-2025-49187 | MEDIUM | 5.3 | 0.3% | Jun 12, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to... |
| CVE-2025-49186 | MEDIUM | 6.5 | 0.3% | Jun 12, 2025 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short tim... |
| CVE-2025-49185 | MEDIUM | 5.4 | 0.2% | Jun 12, 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can... |
| CVE-2025-49184 | HIGH | 7.5 | 0.4% | Jun 12, 2025 | A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of conf... |
| CVE-2025-49183 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor an... |
| CVE-2025-49182 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | Files in the source code contain login credentials for the admin user and the property configuration password, allowing ... |
| CVE-2025-49181 | HIGH | 8.6 | 0.3% | Jun 12, 2025 | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive infor... |
| CVE-2025-6021 | HIGH | 7.5 | 1.2% | Jun 12, 2025 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a ... |
| CVE-2025-5195 | MEDIUM | 4.3 | 0.2% | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now