2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5607 | HIGH | 8.8 | 0.8% | Jun 4, 2025 | A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function form... |
| CVE-2025-48935 | CRITICAL | 9.1 | 0.4% | Jun 4, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is ... |
| CVE-2025-48934 | MEDIUM | 5.3 | 0.4% | Jun 4, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` ... |
| CVE-2025-48888 | MEDIUM | 5.3 | 0.3% | Jun 4, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.... |
| CVE-2025-46339 | MEDIUM | 4.3 | 0.2% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding ... |
| CVE-2025-46204 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint. |
| CVE-2025-46203 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint. |
| CVE-2025-46011 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers... |
| CVE-2025-32015 | MEDIUM | 6.7 | 0.4% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe... |
| CVE-2025-31482 | MEDIUM | 4.3 | 0.2% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedl... |
| CVE-2025-31136 | MEDIUM | 5.4 | 0.3% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the... |
| CVE-2025-31134 | HIGH | 7.5 | 0.4% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information abou... |
| CVE-2025-22245 | MEDIUM | 5.9 | 0.2% | Jun 4, 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validatio... |
| CVE-2025-22244 | MEDIUM | 6.9 | 0.3% | Jun 4, 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input vali... |
| CVE-2025-22243 | HIGH | 7.5 | 0.3% | Jun 4, 2025 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. |
| CVE-2025-5606 | CRITICAL | 9.8 | 3.8% | Jun 4, 2025 | A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the fu... |
| CVE-2025-5604 | CRITICAL | 9.8 | 0.4% | Jun 4, 2025 | A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-5603 | CRITICAL | 9.8 | 0.4% | Jun 4, 2025 | A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-5602 | CRITICAL | 9.8 | 0.4% | Jun 4, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System 1.0. Affected is an... |
| CVE-2025-5600 | CRITICAL | 9.8 | 1.0% | Jun 4, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue... |
| CVE-2025-5599 | CRITICAL | 9.8 | 0.4% | Jun 4, 2025 | A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability ... |
| CVE-2025-5688 | HIGH | 7.5 | 0.3% | Jun 4, 2025 | We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very ... |
| CVE-2025-5596 | CRITICAL | 9.8 | 0.6% | Jun 4, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi... |
| CVE-2025-5595 | CRITICAL | 9.8 | 0.6% | Jun 4, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown proces... |
| CVE-2025-2336 | MEDIUM | 4.8 | 0.4% | Jun 4, 2025 | Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'n... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now