2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48866 | HIGH | 7.5 | 0.8% | Jun 2, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ... |
| CVE-2025-45542 | HIGH | 7.3 | 1.0% | Jun 2, 2025 | SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v... |
| CVE-2025-44115 | MEDIUM | 5.4 | 0.2% | Jun 2, 2025 | A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&... |
| CVE-2025-44172 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement ... |
| CVE-2025-37096 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37095 | CRITICAL | 9.8 | 1.1% | Jun 2, 2025 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-20001 | MEDIUM | 6.5 | 0.5% | Jun 2, 2025 | An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trig... |
| CVE-2025-5447 | CRITICAL | 9.8 | 41.0% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-37094 | CRITICAL | 9.1 | 0.8% | Jun 2, 2025 | A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37093 | CRITICAL | 9.8 | 1.0% | Jun 2, 2025 | An authentication bypass vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37092 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37091 | CRITICAL | 9.8 | 1.2% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37090 | CRITICAL | 9.8 | 0.6% | Jun 2, 2025 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37089 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-5446 | CRITICAL | 9.8 | 21.5% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-5445 | CRITICAL | 9.8 | 21.3% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-48745 | — | — | — | Jun 2, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation d... |
| CVE-2025-46806 | MEDIUM | 6.9 | 0.4% | Jun 2, 2025 | A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue a... |
| CVE-2025-26396 | HIGH | 7.8 | 0.2% | Jun 2, 2025 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal... |
| CVE-2025-5444 | CRITICAL | 9.8 | 21.3% | Jun 2, 2025 | A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-5443 | CRITICAL | 9.8 | 21.3% | Jun 2, 2025 | A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE900... |
| CVE-2025-48990 | HIGH | 8.6 | 0.2% | Jun 2, 2025 | NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`,... |
| CVE-2025-48958 | MEDIUM | 5.4 | 0.3% | Jun 2, 2025 | Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the cu... |
| CVE-2025-48957 | HIGH | 7.5 | 0.6% | Jun 2, 2025 | AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions ... |
| CVE-2025-48955 | MEDIUM | 6.2 | 0.1% | Jun 2, 2025 | Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now