2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32106 | CRITICAL | 9.8 | 0.9% | Jun 3, 2025 | In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated re... |
| CVE-2025-32105 | CRITICAL | 9.8 | 1.1% | Jun 3, 2025 | A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remot... |
| CVE-2025-5509 | CRITICAL | 9.8 | 0.6% | Jun 3, 2025 | A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part... |
| CVE-2025-45854 | CRITICAL | 10 | 2.7% | Jun 3, 2025 | /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams. |
| CVE-2025-44148 | CRITICAL | 9.8 | 54.4% | Jun 3, 2025 | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-5502 | CRITICAL | 9.8 | 7.6% | Jun 3, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this... |
| CVE-2025-5499 | CRITICAL | 9.8 | 0.6% | Jun 3, 2025 | A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function ... |
| CVE-2025-5497 | CRITICAL | 9.8 | 0.5% | Jun 3, 2025 | A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the... |
| CVE-2025-5495 | CRITICAL | 9.8 | 0.8% | Jun 3, 2025 | A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow... |
| CVE-2025-4517 | CRITICAL | 9.4 | 1.2% | Jun 3, 2025 | Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe... |
| CVE-2025-5493 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue ... |
| CVE-2025-4797 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2025-23099 | CRITICAL | 9.1 | 0.4% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou... |
| CVE-2025-5086 | CRITICAL | 9 | 89.1% | Jun 2, 2025 | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l... |
| CVE-2025-37096 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37095 | CRITICAL | 9.8 | 1.1% | Jun 2, 2025 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-5447 | CRITICAL | 9.8 | 41.0% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-37094 | CRITICAL | 9.1 | 0.8% | Jun 2, 2025 | A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37093 | CRITICAL | 9.8 | 1.0% | Jun 2, 2025 | An authentication bypass vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37092 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37091 | CRITICAL | 9.8 | 1.2% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37090 | CRITICAL | 9.8 | 0.6% | Jun 2, 2025 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-37089 | CRITICAL | 9.8 | 1.3% | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. |
| CVE-2025-5446 | CRITICAL | 9.8 | 21.5% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-5445 | CRITICAL | 9.8 | 21.3% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now