2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46638 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo... |
| CVE-2025-52612 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script... |
| CVE-2025-52611 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ... |
| CVE-2025-52609 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by... |
| CVE-2025-52608 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s... |
| CVE-2025-52606 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar... |
| CVE-2025-12694 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t... |
| CVE-2025-71314 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches(... |
| CVE-2025-71313 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_wor... |
| CVE-2025-70101 | MEDIUM | 6.5 | 0.3% | Jun 3, 2026 | An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows att... |
| CVE-2025-70100 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library... |
| CVE-2025-60477 | MEDIUM | 5 | 0.1% | Jun 3, 2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr... |
| CVE-2025-41259 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege... |
| CVE-2025-15656 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe... |
| CVE-2025-15655 | HIGH | 7.6 | 0.2% | Jun 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma... |
| CVE-2025-14774 | HIGH | 7.4 | 0.2% | Jun 3, 2026 | Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. |
| CVE-2025-14773 | MEDIUM | 5.4 | 0.2% | Jun 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. T... |
| CVE-2025-14772 | HIGH | 8.8 | 0.3% | Jun 3, 2026 | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24... |
| CVE-2025-14771 | CRITICAL | 9.9 | 0.3% | Jun 3, 2026 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0... |
| CVE-2025-15654 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague ... |
| CVE-2025-15653 | HIGH | 7 | 0.2% | Jun 2, 2026 | Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability... |
| CVE-2025-64390 | HIGH | 7.4 | 0.1% | Jun 2, 2026 | A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di... |
| CVE-2025-69369 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68886 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58897 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now