2025 CVE Vulnerabilities
45,173 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3898 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou... |
| CVE-2025-3116 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou... |
| CVE-2025-3112 | HIGH | 7.1 | 0.5% | Jun 10, 2025 | CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated... |
| CVE-2025-27819 | HIGH | 7.5 | 0.9% | Jun 10, 2025 | In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Co... |
| CVE-2025-27818 | HIGH | 8.8 | 0.9% | Jun 10, 2025 | A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the clus... |
| CVE-2025-27817 | HIGH | 7.5 | 60.8% | Jun 10, 2025 | A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients a... |
| CVE-2025-4954 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenti... |
| CVE-2025-4840 | HIGH | 7.5 | 0.5% | Jun 10, 2025 | The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter b... |
| CVE-2025-5952 | HIGH | 7.3 | 1.9% | Jun 10, 2025 | A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the f... |
| CVE-2025-5935 | HIGH | 7.5 | 0.8% | Jun 10, 2025 | A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is... |
| CVE-2025-5934 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function... |
| CVE-2025-5912 | HIGH | 8.8 | 0.9% | Jun 10, 2025 | A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4601 | HIGH | 8.8 | 4.2% | Jun 10, 2025 | The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, ... |
| CVE-2025-4387 | HIGH | 8.8 | 0.4% | Jun 10, 2025 | The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missi... |
| CVE-2025-5911 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this ... |
| CVE-2025-5910 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by ... |
| CVE-2025-5909 | HIGH | 8.8 | 1.1% | Jun 10, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected ... |
| CVE-2025-5908 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This... |
| CVE-2025-5907 | HIGH | 8.8 | 3.9% | Jun 10, 2025 | A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability af... |
| CVE-2025-42995 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read acce... |
| CVE-2025-42994 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory rea... |
| CVE-2025-42983 | HIGH | 8.5 | 0.3% | Jun 10, 2025 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, pot... |
| CVE-2025-42982 | HIGH | 8.8 | 0.3% | Jun 10, 2025 | SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control ... |
| CVE-2025-42977 | HIGH | 7.6 | 0.6% | Jun 10, 2025 | SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input pa... |
| CVE-2025-23192 | HIGH | 7.6 | 0.3% | Jun 10, 2025 | SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now