2025 CVE Vulnerabilities
45,269 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22486 | HIGH | 8.8 | 0.2% | Jun 6, 2025 | An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi... |
| CVE-2025-22484 | HIGH | 7.1 | 0.3% | Jun 6, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-22482 | HIGH | 8.1 | 0.3% | Jun 6, 2025 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the ... |
| CVE-2025-22481 | HIGH | 8.8 | 0.9% | Jun 6, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2025-5782 | MEDIUM | 6.3 | 0.2% | Jun 6, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. A... |
| CVE-2025-5780 | HIGH | 7.5 | 0.3% | Jun 6, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-5779 | HIGH | 7.5 | 0.3% | Jun 6, 2025 | A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affecte... |
| CVE-2025-41646 | CRITICAL | 9.8 | 40.7% | Jun 6, 2025 | An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect ... |
| CVE-2025-27531 | CRITICAL | 9.8 | 0.6% | Jun 6, 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before... |
| CVE-2025-5806 | HIGH | 8 | 0.4% | Jun 6, 2025 | Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy... |
| CVE-2025-5791 | HIGH | 7.1 | 0.2% | Jun 6, 2025 | A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listin... |
| CVE-2025-5778 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affecte... |
| CVE-2025-38002 | MEDIUM | 5.5 | 0.2% | Jun 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uri... |
| CVE-2025-38001 | MEDIUM | 5.5 | 0.4% | Jun 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding c... |
| CVE-2025-0620 | MEDIUM | 4.9 | 0.7% | Jun 6, 2025 | A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an e... |
| CVE-2025-5766 | MEDIUM | 4.3 | 0.2% | Jun 6, 2025 | A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability a... |
| CVE-2025-5765 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un... |
| CVE-2025-5764 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s... |
| CVE-2025-49453 | HIGH | 7.1 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allo... |
| CVE-2025-49450 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Gir... |
| CVE-2025-49449 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-... |
| CVE-2025-49446 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.T... |
| CVE-2025-49445 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-ma... |
| CVE-2025-49443 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon ... |
| CVE-2025-49442 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Si... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now