2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34038 | HIGH | 7.5 | 1.8% | Jun 24, 2025 | A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passe... |
| CVE-2025-6535 | HIGH | 8.8 | 0.4% | Jun 24, 2025 | A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerabilit... |
| CVE-2025-34034 | HIGH | 8.8 | 0.6% | Jun 24, 2025 | A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The app... |
| CVE-2025-34033 | HIGH | 8.8 | 3.9% | Jun 24, 2025 | An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ... |
| CVE-2025-34031 | HIGH | 7.5 | 3.0% | Jun 24, 2025 | A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsm... |
| CVE-2025-6529 | HIGH | 8.8 | 0.7% | Jun 23, 2025 | A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknow... |
| CVE-2025-52558 | HIGH | 7 | 0.5% | Jun 23, 2025 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se... |
| CVE-2025-23092 | HIGH | 7.2 | 0.8% | Jun 23, 2025 | Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privil... |
| CVE-2025-48026 | HIGH | 7.5 | 0.5% | Jun 23, 2025 | A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthen... |
| CVE-2025-44528 | HIGH | 7.5 | 0.4% | Jun 23, 2025 | An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of ... |
| CVE-2025-50349 | HIGH | 7.5 | 0.8% | Jun 23, 2025 | PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php. |
| CVE-2025-50348 | HIGH | 7.5 | 0.8% | Jun 23, 2025 | PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php. |
| CVE-2025-49144 | HIGH | 7.3 | 0.4% | Jun 23, 2025 | Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerabilit... |
| CVE-2025-49126 | HIGH | 8.8 | 0.2% | Jun 23, 2025 | Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is... |
| CVE-2025-6516 | HIGH | 7.8 | 0.3% | Jun 23, 2025 | A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function ... |
| CVE-2025-6511 | HIGH | 8.8 | 1.0% | Jun 23, 2025 | A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_4... |
| CVE-2025-6510 | HIGH | 8.8 | 0.8% | Jun 23, 2025 | A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is t... |
| CVE-2025-2171 | HIGH | 7.8 | 0.5% | Jun 23, 2025 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attem... |
| CVE-2025-52922 | HIGH | 7.4 | 0.5% | Jun 23, 2025 | Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access t... |
| CVE-2025-23049 | HIGH | 8.4 | 2.0% | Jun 23, 2025 | Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled. |
| CVE-2025-27387 | HIGH | 7.4 | 0.2% | Jun 23, 2025 | OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure. |
| CVE-2025-6487 | HIGH | 8.8 | 0.8% | Jun 22, 2025 | A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the... |
| CVE-2025-6486 | HIGH | 8.8 | 0.8% | Jun 22, 2025 | A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability ... |
| CVE-2025-6484 | HIGH | 7.2 | 0.5% | Jun 22, 2025 | A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue ... |
| CVE-2025-6422 | HIGH | 8.8 | 0.4% | Jun 21, 2025 | A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now