2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40675 | MEDIUM | 6.1 | 0.2% | Jun 9, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an atta... |
| CVE-2025-5870 | HIGH | 7.3 | 0.4% | Jun 9, 2025 | A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnera... |
| CVE-2025-5869 | CRITICAL | 9.8 | 0.7% | Jun 9, 2025 | A vulnerability, which was classified as critical, was found in RT-Thread 5.1.0. Affected is the function sys_recvfrom o... |
| CVE-2025-5894 | HIGH | 8.8 | 0.5% | Jun 9, 2025 | Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attac... |
| CVE-2025-5868 | CRITICAL | 9.8 | 1.0% | Jun 9, 2025 | A vulnerability, which was classified as critical, has been found in RT-Thread 5.1.0. This issue affects the function sy... |
| CVE-2025-5867 | CRITICAL | 9.8 | 1.0% | Jun 9, 2025 | A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto... |
| CVE-2025-5893 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing... |
| CVE-2025-5866 | CRITICAL | 9.8 | 0.7% | Jun 9, 2025 | A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of t... |
| CVE-2025-5865 | CRITICAL | 9.8 | 0.8% | Jun 9, 2025 | A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_... |
| CVE-2025-5864 | LOW | 3.7 | 0.4% | Jun 9, 2025 | A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnera... |
| CVE-2025-5863 | CRITICAL | 9.8 | 0.8% | Jun 9, 2025 | A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSet... |
| CVE-2025-4652 | MEDIUM | 6.1 | 0.5% | Jun 9, 2025 | The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2025-47712 | MEDIUM | 6.5 | 0.4% | Jun 9, 2025 | A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client... |
| CVE-2025-47711 | MEDIUM | 6.5 | 0.4% | Jun 9, 2025 | There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a c... |
| CVE-2025-3582 | MEDIUM | 4.8 | 0.2% | Jun 9, 2025 | The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3581 | MEDIUM | 4.8 | 0.2% | Jun 9, 2025 | The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting ... |
| CVE-2025-25209 | MEDIUM | 5.7 | 0.2% | Jun 9, 2025 | The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those ... |
| CVE-2025-25208 | MEDIUM | 5.7 | 0.3% | Jun 9, 2025 | A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster |
| CVE-2025-25207 | MEDIUM | 5.7 | 0.3% | Jun 9, 2025 | The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authori... |
| CVE-2025-5862 | CRITICAL | 9.8 | 0.8% | Jun 9, 2025 | A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPP... |
| CVE-2025-5861 | CRITICAL | 9.8 | 4.5% | Jun 9, 2025 | A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the funct... |
| CVE-2025-5860 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Maid Hiring Management System 1.0. This affec... |
| CVE-2025-5859 | HIGH | 8.8 | 0.3% | Jun 9, 2025 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Aff... |
| CVE-2025-5858 | HIGH | 8.8 | 0.3% | Jun 9, 2025 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. A... |
| CVE-2025-5857 | HIGH | 8.8 | 0.4% | Jun 9, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now