2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4383 | CRITICAL | 9.3 | 0.3% | Jun 24, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm.... |
| CVE-2025-6567 | CRITICAL | 9.8 | 0.4% | Jun 24, 2025 | A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss... |
| CVE-2025-32977 | CRITICAL | 9.6 | 0.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-32975 | CRITICAL | 10 | 2.4% | Jun 24, 2025 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.... |
| CVE-2025-6433 | CRITICAL | 9.8 | 0.3% | Jun 24, 2025 | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a... |
| CVE-2025-6427 | CRITICAL | 9.1 | 0.4% | Jun 24, 2025 | An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th... |
| CVE-2025-6424 | CRITICAL | 9.8 | 4.4% | Jun 24, 2025 | A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140... |
| CVE-2025-50213 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ... |
| CVE-2025-48890 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-43879 | CRITICAL | 9.8 | 2.6% | Jun 24, 2025 | WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje... |
| CVE-2025-6560 | CRITICAL | 9.8 | 0.6% | Jun 24, 2025 | Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenti... |
| CVE-2025-6559 | CRITICAL | 9.8 | 1.7% | Jun 24, 2025 | Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote ... |
| CVE-2025-48469 | CRITICAL | 9.6 | 0.4% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public... |
| CVE-2025-34041 | CRITICAL | 10 | 7.0% | Jun 24, 2025 | An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma... |
| CVE-2025-34040 | CRITICAL | 10 | 14.4% | Jun 24, 2025 | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil... |
| CVE-2025-34039 | CRITICAL | 10 | 0.5% | Jun 24, 2025 | A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing ser... |
| CVE-2025-34037 | CRITICAL | 10 | 86.1% | Jun 24, 2025 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /h... |
| CVE-2025-34036 | CRITICAL | 9.8 | 25.3% | Jun 24, 2025 | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service ... |
| CVE-2025-34035 | CRITICAL | 9.8 | 12.3% | Jun 24, 2025 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbintera... |
| CVE-2025-52562 | CRITICAL | 10 | 1.7% | Jun 23, 2025 | Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a direct... |
| CVE-2025-2828 | CRITICAL | 10 | 14.1% | Jun 23, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community pa... |
| CVE-2025-6547 | CRITICAL | 9.1 | 0.4% | Jun 23, 2025 | Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pb... |
| CVE-2025-6545 | CRITICAL | 9.1 | 0.4% | Jun 23, 2025 | Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability i... |
| CVE-2025-6517 | CRITICAL | 9.8 | 0.4% | Jun 23, 2025 | A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add ... |
| CVE-2025-46101 | CRITICAL | 9.8 | 0.6% | Jun 23, 2025 | SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now