2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6087 | CRITICAL | 9.1 | 0.8% | Jun 16, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerabili... |
| CVE-2025-6133 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Projectworlds Life Insurance Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-6132 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unkno... |
| CVE-2025-6179 | CRITICAL | 9.8 | 0.2% | Jun 16, 2025 | Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a loca... |
| CVE-2025-5309 | CRITICAL | 9.8 | 0.9% | Jun 16, 2025 | The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template I... |
| CVE-2025-49796 | CRITICAL | 9.1 | 1.5% | Jun 16, 2025 | A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory ... |
| CVE-2025-49794 | CRITICAL | 9.1 | 0.7% | Jun 16, 2025 | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circums... |
| CVE-2025-3594 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, a... |
| CVE-2025-6124 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects so... |
| CVE-2025-6123 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerabili... |
| CVE-2025-6121 | CRITICAL | 9.8 | 1.9% | Jun 16, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is ... |
| CVE-2025-6118 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affe... |
| CVE-2025-47869 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTO... |
| CVE-2025-47868 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter... |
| CVE-2025-40916 | CRITICAL | 9.1 | 0.3% | Jun 16, 2025 | Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That... |
| CVE-2025-6117 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnera... |
| CVE-2025-6116 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affec... |
| CVE-2025-6172 | CRITICAL | 9.8 | 0.5% | Jun 16, 2025 | Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operatio... |
| CVE-2025-6169 | CRITICAL | 9.8 | 0.5% | Jun 16, 2025 | The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowin... |
| CVE-2025-6098 | CRITICAL | 9.8 | 1.2% | Jun 16, 2025 | A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy... |
| CVE-2025-6097 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function fo... |
| CVE-2025-6095 | CRITICAL | 9.8 | 1.5% | Jun 15, 2025 | A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unk... |
| CVE-2025-36041 | CRITICAL | 9.8 | 0.3% | Jun 15, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-6065 | CRITICAL | 9.1 | 0.8% | Jun 14, 2025 | The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2025-49596 | CRITICAL | 9.4 | 37.0% | Jun 13, 2025 | The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now