2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62850 | HIGH | 7.2 | 0.3% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-58468 | HIGH | 8.8 | 0.2% | Jun 10, 2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ... |
| CVE-2025-71319 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-55657 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack... |
| CVE-2025-52293 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo... |
| CVE-2025-52292 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia... |
| CVE-2025-5090 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil... |
| CVE-2025-5089 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t... |
| CVE-2025-5088 | HIGH | 8.7 | 0.3% | Jun 5, 2026 | An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi... |
| CVE-2025-59174 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v... |
| CVE-2025-8873 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st... |
| CVE-2025-69755 | HIGH | 8.2 | 0.5% | Jun 4, 2026 | An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ... |
| CVE-2025-67448 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not... |
| CVE-2025-59874 | HIGH | 8.1 | 0.3% | Jun 4, 2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak co... |
| CVE-2025-46638 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo... |
| CVE-2025-52612 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script... |
| CVE-2025-12694 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t... |
| CVE-2025-41259 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege... |
| CVE-2025-15656 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe... |
| CVE-2025-15655 | HIGH | 7.6 | 0.2% | Jun 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma... |
| CVE-2025-14774 | HIGH | 7.4 | 0.2% | Jun 3, 2026 | Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. |
| CVE-2025-14772 | HIGH | 8.8 | 0.3% | Jun 3, 2026 | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24... |
| CVE-2025-15654 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague ... |
| CVE-2025-15653 | HIGH | 7 | 0.2% | Jun 2, 2026 | Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability... |
| CVE-2025-64390 | HIGH | 7.4 | 0.1% | Jun 2, 2026 | A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now