2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62858 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2025-71315 | MEDIUM | 5.5 | 0.1% | Jun 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk... |
| CVE-2025-12656 | LOW | 3.8 | 0.3% | Jun 6, 2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de... |
| CVE-2025-71318 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ... |
| CVE-2025-71317 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce... |
| CVE-2025-5090 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil... |
| CVE-2025-5089 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t... |
| CVE-2025-5088 | HIGH | 8.7 | 0.3% | Jun 5, 2026 | An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi... |
| CVE-2025-59174 | HIGH | 7.1 | 0.2% | Jun 5, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v... |
| CVE-2025-8873 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st... |
| CVE-2025-71316 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS... |
| CVE-2025-65640 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.... |
| CVE-2025-69755 | HIGH | 8.2 | 0.5% | Jun 4, 2026 | An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ... |
| CVE-2025-67448 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not... |
| CVE-2025-67447 | CRITICAL | 9.8 | 1.0% | Jun 4, 2026 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje... |
| CVE-2025-67446 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u... |
| CVE-2025-62338 | LOW | 3.3 | 0.1% | Jun 4, 2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized ... |
| CVE-2025-59874 | HIGH | 8.1 | 0.3% | Jun 4, 2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak co... |
| CVE-2025-46638 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo... |
| CVE-2025-52612 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script... |
| CVE-2025-52611 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ... |
| CVE-2025-52609 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by... |
| CVE-2025-52608 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s... |
| CVE-2025-52606 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar... |
| CVE-2025-12694 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now