2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6121 | CRITICAL | 9.8 | 1.9% | Jun 16, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is ... |
| CVE-2025-6118 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affe... |
| CVE-2025-47869 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTO... |
| CVE-2025-47868 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter... |
| CVE-2025-40916 | CRITICAL | 9.1 | 0.3% | Jun 16, 2025 | Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That... |
| CVE-2025-6117 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnera... |
| CVE-2025-6116 | CRITICAL | 9.8 | 0.4% | Jun 16, 2025 | A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affec... |
| CVE-2025-6172 | CRITICAL | 9.8 | 0.5% | Jun 16, 2025 | Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operatio... |
| CVE-2025-6169 | CRITICAL | 9.8 | 0.5% | Jun 16, 2025 | The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowin... |
| CVE-2025-6098 | CRITICAL | 9.8 | 1.2% | Jun 16, 2025 | A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy... |
| CVE-2025-6097 | CRITICAL | 9.8 | 0.6% | Jun 16, 2025 | A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function fo... |
| CVE-2025-6095 | CRITICAL | 9.8 | 1.5% | Jun 15, 2025 | A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unk... |
| CVE-2025-36041 | CRITICAL | 9.8 | 0.3% | Jun 15, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-6065 | CRITICAL | 9.1 | 0.8% | Jun 14, 2025 | The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2025-49596 | CRITICAL | 9.4 | 37.0% | Jun 13, 2025 | The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are ... |
| CVE-2025-6030 | CRITICAL | 9.4 | 0.2% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyc... |
| CVE-2025-6029 | CRITICAL | 9.4 | 0.6% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-br... |
| CVE-2025-28389 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. |
| CVE-2025-28388 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. |
| CVE-2025-28386 | CRITICAL | 9.8 | 0.9% | Jun 13, 2025 | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers ... |
| CVE-2025-28384 | CRITICAL | 9.1 | 0.9% | Jun 13, 2025 | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory trav... |
| CVE-2025-46060 | CRITICAL | 9.8 | 1.0% | Jun 13, 2025 | Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-45988 | CRITICAL | 9.8 | 9.7% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45987 | CRITICAL | 9.8 | 2.3% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45986 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now