2025 CVE Vulnerabilities
45,173 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5905 | HIGH | 8.8 | 7.1% | Jun 10, 2025 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the fun... |
| CVE-2025-5904 | HIGH | 8.8 | 6.9% | Jun 10, 2025 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability... |
| CVE-2025-5903 | HIGH | 8.8 | 6.9% | Jun 10, 2025 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function set... |
| CVE-2025-5902 | HIGH | 8.8 | 3.7% | Jun 9, 2025 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUp... |
| CVE-2025-5901 | HIGH | 8.8 | 3.9% | Jun 9, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the f... |
| CVE-2025-30515 | HIGH | 8.8 | 0.5% | Jun 9, 2025 | CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within... |
| CVE-2025-30507 | HIGH | 7.5 | 0.3% | Jun 9, 2025 | CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injectio... |
| CVE-2025-30183 | HIGH | 8.7 | 0.4% | Jun 9, 2025 | CyberData 011209 Intercom does not properly store or protect web server admin credentials. |
| CVE-2025-26468 | HIGH | 8.7 | 0.3% | Jun 9, 2025 | CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of... |
| CVE-2025-5900 | HIGH | 7.1 | 0.3% | Jun 9, 2025 | A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. ... |
| CVE-2025-49140 | HIGH | 7.5 | 0.4% | Jun 9, 2025 | Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a... |
| CVE-2025-5897 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the functio... |
| CVE-2025-5896 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects un... |
| CVE-2025-49141 | HIGH | 8.8 | 1.5% | Jun 9, 2025 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportS... |
| CVE-2025-49004 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caid... |
| CVE-2025-5914 | HIGH | 7.8 | 0.3% | Jun 9, 2025 | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data... |
| CVE-2025-5895 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataU... |
| CVE-2025-5892 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the f... |
| CVE-2025-49653 | HIGH | 8 | 0.3% | Jun 9, 2025 | Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users o... |
| CVE-2025-49651 | HIGH | 8.1 | 0.3% | Jun 9, 2025 | Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or al... |
| CVE-2025-45001 | HIGH | 7.5 | 0.2% | Jun 9, 2025 | react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chun... |
| CVE-2025-49282 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49281 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49280 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49279 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now