2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5918 | MEDIUM | 6.6 | 0.4% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in... |
| CVE-2025-5917 | MEDIUM | 5 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha... |
| CVE-2025-5916 | MEDIUM | 5.6 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge... |
| CVE-2025-5915 | MEDIUM | 6.6 | 0.2% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the ... |
| CVE-2025-5914 | HIGH | 7.8 | 0.4% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data... |
| CVE-2025-5895 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataU... |
| CVE-2025-5892 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the f... |
| CVE-2025-5891 | MEDIUM | 5.3 | 0.6% | Jun 9, 2025 | A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code ... |
| CVE-2025-5890 | MEDIUM | 5.3 | 0.3% | Jun 9, 2025 | A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape ... |
| CVE-2025-5889 | LOW | 3.1 | 0.4% | Jun 9, 2025 | A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problemat... |
| CVE-2025-5888 | MEDIUM | 6.5 | 0.9% | Jun 9, 2025 | A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerabili... |
| CVE-2025-49653 | HIGH | 8 | 0.3% | Jun 9, 2025 | Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users o... |
| CVE-2025-49652 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ... |
| CVE-2025-49651 | HIGH | 8.1 | 0.3% | Jun 9, 2025 | Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or al... |
| CVE-2025-5887 | MEDIUM | 5.4 | 0.3% | Jun 9, 2025 | A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun... |
| CVE-2025-49136 | MEDIUM | 6.5 | 0.9% | Jun 9, 2025 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to versi... |
| CVE-2025-46041 | MEDIUM | 5.4 | 0.6% | Jun 9, 2025 | A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript ... |
| CVE-2025-45002 | MEDIUM | 5.4 | 0.2% | Jun 9, 2025 | Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my pro... |
| CVE-2025-45001 | HIGH | 7.5 | 0.2% | Jun 9, 2025 | react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chun... |
| CVE-2025-29627 | MEDIUM | 6.8 | 0.3% | Jun 9, 2025 | An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Bio... |
| CVE-2025-5886 | MEDIUM | 4.1 | 0.3% | Jun 9, 2025 | A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing... |
| CVE-2025-49297 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T... |
| CVE-2025-49296 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu... |
| CVE-2025-49295 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This is... |
| CVE-2025-49282 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now