2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28381 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables... |
| CVE-2025-49468 | HIGH | 8.6 | 0.4% | Jun 13, 2025 | A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability al... |
| CVE-2025-39240 | HIGH | 7.2 | 1.1% | Jun 13, 2025 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input ... |
| CVE-2025-22239 | HIGH | 8.1 | 0.2% | Jun 13, 2025 | Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se... |
| CVE-2025-22236 | HIGH | 8.1 | 0.1% | Jun 13, 2025 | Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to ... |
| CVE-2025-5282 | HIGH | 7.5 | 0.3% | Jun 13, 2025 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l... |
| CVE-2025-5491 | HIGH | 8.8 | 0.6% | Jun 13, 2025 | Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a cu... |
| CVE-2025-47959 | HIGH | 7.1 | 5.4% | Jun 13, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize... |
| CVE-2025-30399 | HIGH | 7.5 | 0.9% | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2025-4232 | HIGH | 8.8 | 0.4% | Jun 13, 2025 | An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™... |
| CVE-2025-4231 | HIGH | 7.2 | 1.0% | Jun 13, 2025 | A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform ... |
| CVE-2025-4230 | HIGH | 8.4 | 0.6% | Jun 13, 2025 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas... |
| CVE-2025-27689 | HIGH | 7.8 | 0.1% | Jun 12, 2025 | Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at... |
| CVE-2025-6031 | HIGH | 7.7 | 0.2% | Jun 12, 2025 | Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer act... |
| CVE-2025-5485 | HIGH | 8.8 | 0.4% | Jun 12, 2025 | User names used to access the web management interface are limited to the device identifier, which is a numerical ident... |
| CVE-2025-5484 | HIGH | 8.3 | 0.4% | Jun 12, 2025 | A username and password are required to authenticate to the central SinoTrack device management interface. The username... |
| CVE-2025-44019 | HIGH | 7.1 | 0.4% | Jun 12, 2025 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated... |
| CVE-2025-36539 | HIGH | 7.1 | 0.3% | Jun 12, 2025 | AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticate... |
| CVE-2025-43866 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is ... |
| CVE-2025-5982 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.... |
| CVE-2025-49080 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with networ... |
| CVE-2025-46035 | HIGH | 7.5 | 0.6% | Jun 12, 2025 | Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the o... |
| CVE-2025-49200 | HIGH | 7.5 | 0.4% | Jun 12, 2025 | The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downl... |
| CVE-2025-49198 | HIGH | 7.5 | 0.3% | Jun 12, 2025 | The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of... |
| CVE-2025-49197 | HIGH | 7.5 | 0.2% | Jun 12, 2025 | The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now