2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6296 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this... |
| CVE-2025-6295 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by t... |
| CVE-2025-6294 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is... |
| CVE-2025-6293 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects s... |
| CVE-2025-6282 | CRITICAL | 9.8 | 0.6% | Jun 19, 2025 | A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critic... |
| CVE-2025-6280 | CRITICAL | 9.8 | 0.6% | Jun 19, 2025 | A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is th... |
| CVE-2025-6384 | CRITICAL | 9.1 | 0.9% | Jun 19, 2025 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticate... |
| CVE-2025-6278 | CRITICAL | 9.8 | 0.6% | Jun 19, 2025 | A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.pat... |
| CVE-2025-6277 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This af... |
| CVE-2025-6276 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affe... |
| CVE-2025-33117 | CRITICAL | 9.1 | 0.5% | Jun 19, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that wo... |
| CVE-2025-6267 | CRITICAL | 9.8 | 0.3% | Jun 19, 2025 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated a... |
| CVE-2025-4738 | CRITICAL | 9.8 | 0.3% | Jun 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software ... |
| CVE-2025-6266 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality... |
| CVE-2025-52474 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified... |
| CVE-2025-50201 | CRITICAL | 9.8 | 4.9% | Jun 19, 2025 | WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id... |
| CVE-2025-52467 | CRITICAL | 9.1 | 0.3% | Jun 19, 2025 | pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c... |
| CVE-2025-24288 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default ... |
| CVE-2025-49591 | CRITICAL | 9.1 | 0.4% | Jun 18, 2025 | CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad... |
| CVE-2025-26199 | CRITICAL | 9.8 | 0.5% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm... |
| CVE-2025-26198 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The... |
| CVE-2025-20260 | CRITICAL | 9.8 | 1.5% | Jun 18, 2025 | A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe... |
| CVE-2025-46157 | CRITICAL | 9.9 | 0.8% | Jun 18, 2025 | An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function... |
| CVE-2025-45784 | CRITICAL | 9.8 | 0.5% | Jun 18, 2025 | D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may... |
| CVE-2025-1562 | CRITICAL | 9.8 | 2.9% | Jun 18, 2025 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now