2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6580 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an... |
| CVE-2025-52572 | CRITICAL | 10 | 0.6% | Jun 24, 2025 | Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. ... |
| CVE-2025-6579 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some... |
| CVE-2025-6578 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical.... |
| CVE-2025-52571 | CRITICAL | 9.6 | 0.3% | Jun 24, 2025 | Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It ... |
| CVE-2025-52471 | CRITICAL | 9.8 | 0.7% | Jun 24, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide... |
| CVE-2025-49853 | CRITICAL | 9.3 | 0.4% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke... |
| CVE-2025-49851 | CRITICAL | 9.8 | 0.5% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability wh... |
| CVE-2025-2566 | CRITICAL | 9.3 | 0.5% | Jun 24, 2025 | Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated atta... |
| CVE-2025-4378 | CRITICAL | 10 | 0.3% | Jun 24, 2025 | Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A... |
| CVE-2025-4383 | CRITICAL | 9.3 | 0.3% | Jun 24, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm.... |
| CVE-2025-6567 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss... |
| CVE-2025-32977 | CRITICAL | 9.6 | 0.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-32975 | CRITICAL | 10 | 2.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-6433 | CRITICAL | 9.8 | 0.2% | Jun 24, 2025 | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a... |
| CVE-2025-6427 | CRITICAL | 9.1 | 0.3% | Jun 24, 2025 | An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th... |
| CVE-2025-6424 | CRITICAL | 9.8 | 3.1% | Jun 24, 2025 | A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140... |
| CVE-2025-50213 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ... |
| CVE-2025-48890 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-43879 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-6560 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenti... |
| CVE-2025-6559 | CRITICAL | 9.8 | 1.7% | Jun 24, 2025 | Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote ... |
| CVE-2025-48469 | CRITICAL | 9.6 | 0.4% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public... |
| CVE-2025-34041 | CRITICAL | 10 | 7.0% | Jun 24, 2025 | An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma... |
| CVE-2025-34040 | CRITICAL | 10 | 14.4% | Jun 24, 2025 | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now