2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53007 | HIGH | 8.9 | 0.4% | Jun 26, 2025 | arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response Spli... |
| CVE-2025-52887 | HIGH | 7.5 | 0.4% | Jun 26, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http head... |
| CVE-2025-51672 | HIGH | 8 | 0.4% | Jun 26, 2025 | A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. T... |
| CVE-2025-6710 | HIGH | 7.5 | 0.3% | Jun 26, 2025 | MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON input... |
| CVE-2025-6709 | HIGH | 7.5 | 0.5% | Jun 26, 2025 | The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values ... |
| CVE-2025-6706 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior... |
| CVE-2025-48921 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affec... |
| CVE-2025-6693 | HIGH | 8.5 | 0.2% | Jun 26, 2025 | A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_dev... |
| CVE-2025-6562 | HIGH | 8.8 | 0.9% | Jun 26, 2025 | Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow... |
| CVE-2025-5966 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by f... |
| CVE-2025-5366 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read... |
| CVE-2025-3771 | HIGH | 7.1 | 0.1% | Jun 26, 2025 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin loc... |
| CVE-2025-5459 | HIGH | 8.8 | 0.4% | Jun 26, 2025 | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute com... |
| CVE-2025-37101 | HIGH | 8.7 | 0.3% | Jun 26, 2025 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou... |
| CVE-2025-2938 | HIGH | 8.8 | 0.3% | Jun 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18... |
| CVE-2025-6624 | HIGH | 7.2 | 0.2% | Jun 26, 2025 | Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through ... |
| CVE-2025-5590 | HIGH | 8.8 | 0.3% | Jun 26, 2025 | The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all... |
| CVE-2025-6667 | HIGH | 8.8 | 0.3% | Jun 25, 2025 | A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is s... |
| CVE-2025-6661 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-6660 | HIGH | 7.8 | 0.3% | Jun 25, 2025 | PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2025-6659 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6654 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6651 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6647 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-6645 | HIGH | 7.8 | 0.2% | Jun 25, 2025 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now