2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6319 | HIGH | 8.8 | 0.3% | Jun 20, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This i... |
| CVE-2025-6309 | HIGH | 8.8 | 0.3% | Jun 20, 2025 | A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this v... |
| CVE-2025-6308 | HIGH | 8.8 | 0.3% | Jun 20, 2025 | A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a... |
| CVE-2025-6302 | HIGH | 8.8 | 0.8% | Jun 20, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the... |
| CVE-2025-6292 | HIGH | 8.8 | 0.9% | Jun 20, 2025 | A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the functio... |
| CVE-2025-6291 | HIGH | 8.8 | 0.9% | Jun 20, 2025 | A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file o... |
| CVE-2025-49715 | HIGH | 7.5 | 0.7% | Jun 20, 2025 | Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows... |
| CVE-2025-47771 | HIGH | 8.1 | 0.4% | Jun 20, 2025 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there ... |
| CVE-2025-6283 | HIGH | 7.5 | 0.6% | Jun 19, 2025 | A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the func... |
| CVE-2025-6279 | HIGH | 8 | 0.5% | Jun 19, 2025 | A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the functi... |
| CVE-2025-33121 | HIGH | 7.1 | 0.4% | Jun 19, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when... |
| CVE-2025-52464 | HIGH | 8.3 | 0.4% | Jun 19, 2025 | Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure o... |
| CVE-2025-6019 | HIGH | 7 | 0.4% | Jun 19, 2025 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polk... |
| CVE-2025-5071 | HIGH | 8.8 | 0.6% | Jun 19, 2025 | The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ... |
| CVE-2025-49763 | HIGH | 7.5 | 0.6% | Jun 19, 2025 | ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou... |
| CVE-2025-31698 | HIGH | 7.5 | 0.4% | Jun 19, 2025 | ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users ... |
| CVE-2025-23173 | HIGH | 7.5 | 0.5% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D... |
| CVE-2025-23172 | HIGH | 7.2 | 0.9% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP e... |
| CVE-2025-23171 | HIGH | 7.2 | 0.5% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director... |
| CVE-2025-23168 | HIGH | 8.8 | 0.3% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OT... |
| CVE-2025-23121 | HIGH | 8.8 | 11.6% | Jun 19, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
| CVE-2025-6192 | HIGH | 8.8 | 0.4% | Jun 18, 2025 | Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap... |
| CVE-2025-6191 | HIGH | 8.8 | 8.8% | Jun 18, 2025 | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of ... |
| CVE-2025-29646 | HIGH | 7.1 | 0.3% | Jun 18, 2025 | An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se... |
| CVE-2025-20271 | HIGH | 8.6 | 0.5% | Jun 18, 2025 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now