2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34046 | CRITICAL | 10 | 0.8% | Jun 26, 2025 | An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera... |
| CVE-2025-34044 | CRITICAL | 9.4 | 4.6% | Jun 26, 2025 | A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router ... |
| CVE-2025-34043 | CRITICAL | 10 | 9.0% | Jun 26, 2025 | A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu... |
| CVE-2025-34042 | CRITICAL | 9.4 | 1.8% | Jun 26, 2025 | An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via ... |
| CVE-2025-53002 | CRITICAL | 9.8 | 1.0% | Jun 26, 2025 | LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa... |
| CVE-2025-29331 | CRITICAL | 9.8 | 0.4% | Jun 26, 2025 | An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme... |
| CVE-2025-49003 | CRITICAL | 9.8 | 0.8% | Jun 26, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m... |
| CVE-2025-6561 | CRITICAL | 9.8 | 0.5% | Jun 26, 2025 | Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne... |
| CVE-2025-4334 | CRITICAL | 9.8 | 2.1% | Jun 26, 2025 | The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu... |
| CVE-2025-6668 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This aff... |
| CVE-2025-6665 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-36038 | CRITICAL | 9.8 | 8.0% | Jun 25, 2025 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with ... |
| CVE-2025-6621 | CRITICAL | 9.8 | 2.7% | Jun 25, 2025 | A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSet... |
| CVE-2025-6620 | CRITICAL | 9.8 | 2.7% | Jun 25, 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the f... |
| CVE-2025-6619 | CRITICAL | 9.8 | 2.7% | Jun 25, 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerabili... |
| CVE-2025-6618 | CRITICAL | 9.8 | 2.7% | Jun 25, 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function S... |
| CVE-2025-52483 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi... |
| CVE-2025-52480 | CRITICAL | 9.8 | 0.6% | Jun 25, 2025 | Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi... |
| CVE-2025-49153 | CRITICAL | 9.3 | 0.7% | Jun 25, 2025 | The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code. |
| CVE-2025-49151 | CRITICAL | 9.3 | 0.5% | Jun 25, 2025 | The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authent... |
| CVE-2025-20282 | CRITICAL | 10 | 9.8% | Jun 25, 2025 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upl... |
| CVE-2025-6612 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue af... |
| CVE-2025-6611 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulne... |
| CVE-2025-20281 | CRITICAL | 10 | 96.7% | Jun 25, 2025 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec... |
| CVE-2025-6543 | CRITICAL | 9.8 | 9.8% | Jun 25, 2025 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Ga... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now