2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10237 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller fi... |
| CVE-2025-71330 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-71329 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-6254 | CRITICAL | 9.8 | 0.5% | Jun 10, 2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8... |
| CVE-2025-8444 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl... |
| CVE-2025-66281 | HIGH | 7.2 | 0.5% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ... |
| CVE-2025-66280 | HIGH | 7.2 | 0.4% | Jun 10, 2026 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a... |
| CVE-2025-66279 | HIGH | 7.2 | 1.0% | Jun 10, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2025-66273 | HIGH | 7.2 | 1.0% | Jun 10, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2025-62851 | MEDIUM | 4.4 | 0.3% | Jun 10, 2026 | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac... |
| CVE-2025-62850 | HIGH | 7.2 | 0.3% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-66276 | CRITICAL | 9.8 | 0.3% | Jun 10, 2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250... |
| CVE-2025-59382 | LOW | 1.2 | 0.3% | Jun 10, 2026 | QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version: |
| CVE-2025-58468 | HIGH | 8.8 | 0.2% | Jun 10, 2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ... |
| CVE-2025-71319 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-55659 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker... |
| CVE-2025-55658 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media... |
| CVE-2025-55657 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack... |
| CVE-2025-55651 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows... |
| CVE-2025-52293 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo... |
| CVE-2025-52292 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia... |
| CVE-2025-54509 | MEDIUM | 4 | 0.1% | Jun 9, 2026 | Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg... |
| CVE-2025-67862 | MEDIUM | 6.7 | 0.1% | Jun 9, 2026 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti... |
| CVE-2025-40808 | MEDIUM | 6.9 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),... |
| CVE-2025-10263 | CRITICAL | 9.1 | 0.6% | Jun 9, 2026 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now