2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10262 | MEDIUM | 6.3 | 0.1% | Jun 16, 2026 | Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu... |
| CVE-2025-69332 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | Subscriber Broken Access Control in Bookify <= 1.1.1 versions. |
| CVE-2025-68872 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. |
| CVE-2025-68851 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. |
| CVE-2025-68840 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. |
| CVE-2025-68049 | MEDIUM | 6.3 | 0.2% | Jun 15, 2026 | Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. |
| CVE-2025-60175 | MEDIUM | 4.4 | 0.2% | Jun 15, 2026 | Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions. |
| CVE-2025-59133 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions. |
| CVE-2025-70102 | MEDIUM | 6.3 | 0.2% | Jun 15, 2026 | A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options.... |
| CVE-2025-68713 | HIGH | 8 | 0.3% | Jun 15, 2026 | An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. T... |
| CVE-2025-56814 | HIGH | 7.8 | 0.2% | Jun 15, 2026 | A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code... |
| CVE-2025-55663 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attacke... |
| CVE-2025-55661 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial ... |
| CVE-2025-55660 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to ... |
| CVE-2025-55652 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers t... |
| CVE-2025-55650 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker... |
| CVE-2025-55649 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attack... |
| CVE-2025-55648 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows... |
| CVE-2025-55647 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to c... |
| CVE-2025-55645 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to ... |
| CVE-2025-55644 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker... |
| CVE-2025-55643 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attacke... |
| CVE-2025-55642 | MEDIUM | 6.5 | 0.4% | Jun 15, 2026 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ... |
| CVE-2025-55641 | MEDIUM | 5.5 | 0.2% | Jun 15, 2026 | A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows a... |
| CVE-2025-15659 | MEDIUM | 6.5 | 0.1% | Jun 15, 2026 | Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now