2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6706 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior... |
| CVE-2025-48921 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affec... |
| CVE-2025-6693 | HIGH | 8.5 | 0.2% | Jun 26, 2025 | A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_dev... |
| CVE-2025-6562 | HIGH | 8.8 | 0.9% | Jun 26, 2025 | Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow... |
| CVE-2025-5966 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by f... |
| CVE-2025-5366 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read... |
| CVE-2025-3771 | HIGH | 7.1 | 0.1% | Jun 26, 2025 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin loc... |
| CVE-2025-5459 | HIGH | 8.8 | 0.4% | Jun 26, 2025 | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute com... |
| CVE-2025-37101 | HIGH | 8.7 | 0.3% | Jun 26, 2025 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou... |
| CVE-2025-2938 | HIGH | 8.8 | 0.3% | Jun 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18... |
| CVE-2025-6624 | HIGH | 7.2 | 0.2% | Jun 26, 2025 | Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through ... |
| CVE-2025-5590 | HIGH | 8.8 | 0.3% | Jun 26, 2025 | The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all... |
| CVE-2025-6667 | HIGH | 8.8 | 0.3% | Jun 25, 2025 | A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is s... |
| CVE-2025-6661 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-6660 | HIGH | 7.8 | 0.3% | Jun 25, 2025 | PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2025-6659 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6654 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6651 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6647 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6645 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-6644 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-6642 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows re... |
| CVE-2025-6640 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-6443 | HIGH | 7.2 | 0.5% | Jun 25, 2025 | Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to b... |
| CVE-2025-45333 | HIGH | 7.5 | 0.4% | Jun 25, 2025 | berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now