2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5550 | CRITICAL | 9.8 | 0.6% | Jun 4, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown... |
| CVE-2025-5549 | CRITICAL | 9.8 | 0.6% | Jun 4, 2025 | A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is... |
| CVE-2025-5548 | CRITICAL | 9.8 | 10.1% | Jun 4, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio... |
| CVE-2025-5547 | CRITICAL | 9.8 | 0.6% | Jun 4, 2025 | A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u... |
| CVE-2025-49002 | CRITICAL | 9.8 | 41.8% | Jun 3, 2025 | DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a f... |
| CVE-2025-49001 | CRITICAL | 9.8 | 19.4% | Jun 3, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verificat... |
| CVE-2025-48951 | CRITICAL | 9.3 | 0.6% | Jun 3, 2025 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulne... |
| CVE-2025-23097 | CRITICAL | 9.1 | 0.4% | Jun 3, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds write... |
| CVE-2025-5512 | CRITICAL | 9.8 | 0.7% | Jun 3, 2025 | A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknow... |
| CVE-2025-5510 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknow... |
| CVE-2025-32106 | CRITICAL | 9.8 | 0.9% | Jun 3, 2025 | In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated re... |
| CVE-2025-32105 | CRITICAL | 9.8 | 1.1% | Jun 3, 2025 | A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remot... |
| CVE-2025-5509 | CRITICAL | 9.8 | 0.6% | Jun 3, 2025 | A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part... |
| CVE-2025-45854 | CRITICAL | 10 | 2.7% | Jun 3, 2025 | /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams. |
| CVE-2025-44148 | CRITICAL | 9.8 | 54.4% | Jun 3, 2025 | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-5502 | CRITICAL | 9.8 | 7.6% | Jun 3, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this... |
| CVE-2025-5499 | CRITICAL | 9.8 | 0.6% | Jun 3, 2025 | A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function ... |
| CVE-2025-5497 | CRITICAL | 9.8 | 0.5% | Jun 3, 2025 | A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the... |
| CVE-2025-5495 | CRITICAL | 9.8 | 0.8% | Jun 3, 2025 | A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow... |
| CVE-2025-4517 | CRITICAL | 9.4 | 1.2% | Jun 3, 2025 | Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe... |
| CVE-2025-5493 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue ... |
| CVE-2025-4797 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2025-23099 | CRITICAL | 9.1 | 0.4% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou... |
| CVE-2025-5086 | CRITICAL | 9 | 89.1% | Jun 2, 2025 | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l... |
| CVE-2025-37096 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now