2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49710 | CRITICAL | 9.8 | 0.7% | Jun 11, 2025 | An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir... |
| CVE-2025-49709 | CRITICAL | 9.8 | 0.6% | Jun 11, 2025 | Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. |
| CVE-2025-41663 | CRITICAL | 9.8 | 0.5% | Jun 11, 2025 | For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman... |
| CVE-2025-5980 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affect... |
| CVE-2025-5979 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an u... |
| CVE-2025-5977 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. This issue affects... |
| CVE-2025-36852 | CRITICAL | 9.4 | 0.2% | Jun 10, 2025 | A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remo... |
| CVE-2025-2474 | CRITICAL | 9.8 | 0.6% | Jun 10, 2025 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2025-40585 | CRITICAL | 9.9 | 0.3% | Jun 10, 2025 | A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain... |
| CVE-2025-30220 | CRITICAL | 9.1 | 49.2% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl... |
| CVE-2025-49507 | CRITICAL | 9.8 | 0.5% | Jun 10, 2025 | Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect... |
| CVE-2025-49455 | CRITICAL | 9.3 | 0.4% | Jun 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor... |
| CVE-2025-43698 | CRITICAL | 9.1 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec... |
| CVE-2025-40657 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40656 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40655 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40654 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-1041 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v... |
| CVE-2025-5913 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue ... |
| CVE-2025-5906 | CRITICAL | 9.8 | 0.5% | Jun 10, 2025 | A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part ... |
| CVE-2025-42989 | CRITICAL | 9.6 | 0.4% | Jun 10, 2025 | RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio... |
| CVE-2025-30184 | CRITICAL | 9.8 | 0.5% | Jun 9, 2025 | CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path. |
| CVE-2025-49652 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ... |
| CVE-2025-49297 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T... |
| CVE-2025-49296 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now