2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45985 | CRITICAL | 9.8 | 7.1% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26... |
| CVE-2025-45984 | CRITICAL | 9.8 | 1.8% | Jun 13, 2025 | Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT... |
| CVE-2025-29902 | CRITICAL | 10 | 1.0% | Jun 13, 2025 | Remote code execution that allows unauthorized users to execute arbitrary code on the server machine. |
| CVE-2025-46783 | CRITICAL | 9.8 | 0.8% | Jun 13, 2025 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability... |
| CVE-2025-5288 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri... |
| CVE-2025-43863 | CRITICAL | 9.8 | 0.4% | Jun 12, 2025 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2025-49467 | CRITICAL | 9.3 | 0.3% | Jun 12, 2025 | A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension i... |
| CVE-2025-49199 | CRITICAL | 9.8 | 0.3% | Jun 12, 2025 | The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP... |
| CVE-2025-49196 | CRITICAL | 9.1 | 0.2% | Jun 12, 2025 | A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati... |
| CVE-2025-49195 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user pas... |
| CVE-2025-49182 | CRITICAL | 9.8 | 0.5% | Jun 12, 2025 | Files in the source code contain login credentials for the admin user and the property configuration password, allowing ... |
| CVE-2025-4973 | CRITICAL | 9.8 | 0.4% | Jun 12, 2025 | The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen... |
| CVE-2025-30085 | CRITICAL | 9.2 | 0.5% | Jun 11, 2025 | Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs w... |
| CVE-2025-40912 | CRITICAL | 9.8 | 0.4% | Jun 11, 2025 | CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds ... |
| CVE-2025-40914 | CRITICAL | 9.8 | 0.4% | Jun 11, 2025 | Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a ... |
| CVE-2025-49710 | CRITICAL | 9.8 | 0.7% | Jun 11, 2025 | An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir... |
| CVE-2025-49709 | CRITICAL | 9.8 | 0.7% | Jun 11, 2025 | Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. |
| CVE-2025-41663 | CRITICAL | 9.8 | 0.5% | Jun 11, 2025 | For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman... |
| CVE-2025-5980 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affect... |
| CVE-2025-5979 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an u... |
| CVE-2025-5977 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. This issue affects... |
| CVE-2025-36852 | CRITICAL | 9.4 | 0.2% | Jun 10, 2025 | A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remo... |
| CVE-2025-2474 | CRITICAL | 9.8 | 0.6% | Jun 10, 2025 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2025-40585 | CRITICAL | 9.9 | 0.3% | Jun 10, 2025 | A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain... |
| CVE-2025-30220 | CRITICAL | 9.1 | 49.2% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now