2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49164 | MEDIUM | 4.3 | 0.1% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a48... |
| CVE-2025-49163 | MEDIUM | 6.7 | 0.1% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip ... |
| CVE-2025-49162 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a ... |
| CVE-2025-3919 | MEDIUM | 6.4 | 0.2% | Jun 2, 2025 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2025-48996 | MEDIUM | 5.3 | 0.3% | Jun 2, 2025 | HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthentic... |
| CVE-2025-48387 | HIGH | 8.7 | 0.5% | Jun 2, 2025 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an ex... |
| CVE-2025-47585 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme... |
| CVE-2025-49069 | MEDIUM | 4.3 | 0.1% | Jun 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Requ... |
| CVE-2025-23105 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo... |
| CVE-2025-23099 | CRITICAL | 9.1 | 0.4% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou... |
| CVE-2025-1051 | HIGH | 8.8 | 0.3% | Jun 2, 2025 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent... |
| CVE-2025-5086 | CRITICAL | 9 | 89.1% | Jun 2, 2025 | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l... |
| CVE-2025-45387 | MEDIUM | 5.4 | 0.2% | Jun 2, 2025 | osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php. |
| CVE-2025-27956 | HIGH | 7.5 | 1.1% | Jun 2, 2025 | Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via th... |
| CVE-2025-27955 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and... |
| CVE-2025-27954 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut... |
| CVE-2025-27953 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut... |
| CVE-2025-23104 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privi... |
| CVE-2025-20298 | HIGH | 8 | 0.2% | Jun 2, 2025 | In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to... |
| CVE-2025-20297 | MEDIUM | 5.4 | 13.1% | Jun 2, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2... |
| CVE-2025-5036 | HIGH | 7.8 | 0.2% | Jun 2, 2025 | A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A... |
| CVE-2025-48995 | MEDIUM | 6.9 | 0.2% | Jun 2, 2025 | SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat... |
| CVE-2025-48994 | MEDIUM | 6.9 | 0.2% | Jun 2, 2025 | SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat... |
| CVE-2025-48941 | MEDIUM | 5.3 | 0.3% | Jun 2, 2025 | MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions... |
| CVE-2025-48940 | HIGH | 7.2 | 0.5% | Jun 2, 2025 | MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now