2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48997 | HIGH | 8.7 | 0.4% | Jun 3, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1... |
| CVE-2025-48950 | HIGH | 8.8 | 0.4% | Jun 3, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p... |
| CVE-2025-23102 | HIGH | 8.8 | 0.4% | Jun 3, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Doub... |
| CVE-2025-5511 | HIGH | 7.5 | 0.6% | Jun 3, 2025 | A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affec... |
| CVE-2025-30167 | HIGH | 7.3 | 0.2% | Jun 3, 2025 | Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to versio... |
| CVE-2025-23107 | HIGH | 8.6 | 0.3% | Jun 3, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou... |
| CVE-2025-25022 | HIGH | 8.8 | 0.3% | Jun 3, 2025 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all... |
| CVE-2025-25021 | HIGH | 7.2 | 0.5% | Jun 3, 2025 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all... |
| CVE-2025-23103 | HIGH | 8.6 | 0.3% | Jun 3, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou... |
| CVE-2025-5503 | HIGH | 8.8 | 3.6% | Jun 3, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the func... |
| CVE-2025-36564 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal... |
| CVE-2025-5498 | HIGH | 7.2 | 0.4% | Jun 3, 2025 | A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the... |
| CVE-2025-46154 | HIGH | 8.4 | 0.2% | Jun 3, 2025 | Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php. |
| CVE-2025-4435 | HIGH | 7.5 | 0.5% | Jun 3, 2025 | When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members wo... |
| CVE-2025-4330 | HIGH | 7.5 | 0.8% | Jun 3, 2025 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the... |
| CVE-2025-4138 | HIGH | 7.5 | 1.1% | Jun 3, 2025 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the... |
| CVE-2025-5492 | HIGH | 8.8 | 2.9% | Jun 3, 2025 | A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnera... |
| CVE-2025-4392 | HIGH | 7.2 | 0.3% | Jun 3, 2025 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2025-31359 | HIGH | 8.8 | 1.7% | Jun 3, 2025 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers... |
| CVE-2025-46355 | HIGH | 7.3 | 0.1% | Jun 3, 2025 | Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY... |
| CVE-2025-21479 | HIGH | 8.6 | 0.7% | Jun 3, 2025 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
| CVE-2025-31710 | HIGH | 8.4 | 0.4% | Jun 3, 2025 | In engineermode service, there is a possible command injection due to improper input validation. This could lead to loca... |
| CVE-2025-27038 | HIGH | 7.5 | 0.8% | Jun 3, 2025 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. |
| CVE-2025-27031 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed. |
| CVE-2025-27029 | HIGH | 7.5 | 0.2% | Jun 3, 2025 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now