2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49549 | LOW | 2.7 | 0.3% | Jun 25, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author... |
| CVE-2025-52889 | LOW | 3.4 | 0.2% | Jun 25, 2025 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers... |
| CVE-2025-4656 | LOW | 3.1 | 0.2% | Jun 25, 2025 | Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontroll... |
| CVE-2025-52884 | LOW | 1.7 | 0.3% | Jun 24, 2025 | RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repos... |
| CVE-2025-52570 | LOW | 1.7 | 0.3% | Jun 24, 2025 | Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. I... |
| CVE-2025-48463 | LOW | 3.1 | 0.1% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on ... |
| CVE-2025-6536 | LOW | 3.3 | 0.1% | Jun 24, 2025 | A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is... |
| CVE-2025-6527 | LOW | 3.1 | 0.5% | Jun 23, 2025 | A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown fun... |
| CVE-2025-6524 | LOW | 3.1 | 0.3% | Jun 23, 2025 | A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the... |
| CVE-2025-6509 | LOW | 3.5 | 0.2% | Jun 23, 2025 | A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been decl... |
| CVE-2025-4563 | LOW | 2.7 | 0.7% | Jun 23, 2025 | A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation au... |
| CVE-2025-52968 | LOW | 2.7 | 0.2% | Jun 23, 2025 | xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (Fo... |
| CVE-2025-52937 | LOW | 2 | 0.1% | Jun 23, 2025 | Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with p... |
| CVE-2025-6497 | LOW | 3.3 | 0.1% | Jun 23, 2025 | A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function p... |
| CVE-2025-52926 | LOW | 2.7 | 0.1% | Jun 23, 2025 | In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface... |
| CVE-2025-6496 | LOW | 3.3 | 0.1% | Jun 23, 2025 | A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the... |
| CVE-2025-6494 | LOW | 3.3 | 0.1% | Jun 22, 2025 | A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as ... |
| CVE-2025-6490 | LOW | 3.3 | 0.1% | Jun 22, 2025 | A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problemat... |
| CVE-2025-52916 | LOW | 2.2 | 0.3% | Jun 21, 2025 | Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits). |
| CVE-2025-6401 | LOW | 3.5 | 0.4% | Jun 21, 2025 | A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an... |
| CVE-2025-6217 | LOW | 2.5 | 0.1% | Jun 21, 2025 | PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure Vulnerability. This vulnerability... |
| CVE-2025-52484 | LOW | 2.7 | 0.2% | Jun 20, 2025 | RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constrai... |
| CVE-2025-48059 | LOW | 2.7 | 0.5% | Jun 20, 2025 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criter... |
| CVE-2025-5416 | LOW | 2.7 | 0.2% | Jun 20, 2025 | A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it require... |
| CVE-2025-47293 | LOW | 2.7 | 0.4% | Jun 19, 2025 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now