2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6030 | CRITICAL | 9.4 | 0.2% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyc... |
| CVE-2025-6029 | CRITICAL | 9.4 | 0.6% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-br... |
| CVE-2025-28389 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. |
| CVE-2025-28388 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. |
| CVE-2025-28386 | CRITICAL | 9.8 | 0.9% | Jun 13, 2025 | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers ... |
| CVE-2025-28384 | CRITICAL | 9.1 | 0.9% | Jun 13, 2025 | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory trav... |
| CVE-2025-46060 | CRITICAL | 9.8 | 1.0% | Jun 13, 2025 | Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-45988 | CRITICAL | 9.8 | 9.7% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45987 | CRITICAL | 9.8 | 2.3% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45986 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45985 | CRITICAL | 9.8 | 7.1% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45984 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT... |
| CVE-2025-29902 | CRITICAL | 10 | 1.0% | Jun 13, 2025 | Remote code execution that allows unauthorized users to execute arbitrary code on the server machine. |
| CVE-2025-46783 | CRITICAL | 9.8 | 0.8% | Jun 13, 2025 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability... |
| CVE-2025-5288 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri... |
| CVE-2025-43863 | CRITICAL | 9.8 | 0.4% | Jun 12, 2025 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2025-49467 | CRITICAL | 9.3 | 0.3% | Jun 12, 2025 | A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension i... |
| CVE-2025-49199 | CRITICAL | 9.8 | 0.3% | Jun 12, 2025 | The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP... |
| CVE-2025-49196 | CRITICAL | 9.1 | 0.2% | Jun 12, 2025 | A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati... |
| CVE-2025-49195 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user pas... |
| CVE-2025-49182 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | Files in the source code contain login credentials for the admin user and the property configuration password, allowing ... |
| CVE-2025-4973 | CRITICAL | 9.8 | 0.4% | Jun 12, 2025 | The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen... |
| CVE-2025-30085 | CRITICAL | 9.2 | 0.5% | Jun 11, 2025 | Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs w... |
| CVE-2025-40912 | CRITICAL | 9.8 | 0.4% | Jun 11, 2025 | CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds ... |
| CVE-2025-40914 | CRITICAL | 9.8 | 0.4% | Jun 11, 2025 | Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now