2025 CVE Vulnerabilities
45,269 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41366 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing... |
| CVE-2025-41365 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st... |
| CVE-2025-41364 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allow... |
| CVE-2025-41363 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing... |
| CVE-2025-41362 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st... |
| CVE-2025-41361 | HIGH | 8.3 | 0.2% | Jun 6, 2025 | Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly h... |
| CVE-2025-41360 | HIGH | 8.7 | 0.3% | Jun 6, 2025 | Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The device is vulnerable... |
| CVE-2025-39358 | HIGH | 8.8 | 0.4% | Jun 6, 2025 | Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Inject... |
| CVE-2025-5759 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This ... |
| CVE-2025-5758 | HIGH | 7.3 | 0.4% | Jun 6, 2025 | A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This a... |
| CVE-2025-5757 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec... |
| CVE-2025-5756 | CRITICAL | 9.8 | 0.5% | Jun 6, 2025 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical.... |
| CVE-2025-5755 | HIGH | 7.3 | 0.4% | Jun 6, 2025 | A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical... |
| CVE-2025-5192 | HIGH | 7.5 | 0.4% | Jun 6, 2025 | A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource ... |
| CVE-2025-48784 | HIGH | 7.5 | 0.3% | Jun 6, 2025 | A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 a... |
| CVE-2025-48783 | HIGH | 7.5 | 0.3% | Jun 6, 2025 | An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Mana... |
| CVE-2025-48782 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Res... |
| CVE-2025-48781 | HIGH | 7.5 | 0.4% | Jun 6, 2025 | An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Ma... |
| CVE-2025-48780 | CRITICAL | 9.8 | 0.5% | Jun 6, 2025 | A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Managem... |
| CVE-2025-5739 | HIGH | 8.8 | 4.2% | Jun 6, 2025 | A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part... |
| CVE-2025-5738 | HIGH | 8.8 | 0.6% | Jun 6, 2025 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is... |
| CVE-2025-5737 | HIGH | 8.8 | 0.6% | Jun 6, 2025 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulne... |
| CVE-2025-3365 | CRITICAL | 9.8 | 0.5% | Jun 6, 2025 | A missing protection against path traversal allows to access any file on the server. |
| CVE-2025-3322 | CRITICAL | 10 | 0.6% | Jun 6, 2025 | An improper neutralization of inputs used in expression language allows remote code execution with the highest privilege... |
| CVE-2025-5736 | HIGH | 8.8 | 0.8% | Jun 6, 2025 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now