2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21486 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. |
| CVE-2025-21485 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. |
| CVE-2025-21480 | HIGH | 8.6 | 0.4% | Jun 3, 2025 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. |
| CVE-2025-21463 | HIGH | 7.5 | 0.2% | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. |
| CVE-2025-4224 | HIGH | 7.2 | 0.2% | Jun 3, 2025 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl... |
| CVE-2025-5419 | HIGH | 8.8 | 6.5% | Jun 3, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl... |
| CVE-2025-5068 | HIGH | 8.8 | 2.6% | Jun 3, 2025 | Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-48387 | HIGH | 8.7 | 0.5% | Jun 2, 2025 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an ex... |
| CVE-2025-23105 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo... |
| CVE-2025-1051 | HIGH | 8.8 | 0.3% | Jun 2, 2025 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent... |
| CVE-2025-27956 | HIGH | 7.5 | 1.1% | Jun 2, 2025 | Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via th... |
| CVE-2025-20298 | HIGH | 8 | 0.2% | Jun 2, 2025 | In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to... |
| CVE-2025-5036 | HIGH | 7.8 | 0.2% | Jun 2, 2025 | A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A... |
| CVE-2025-48940 | HIGH | 7.2 | 0.5% | Jun 2, 2025 | MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input... |
| CVE-2025-48866 | HIGH | 7.5 | 0.8% | Jun 2, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ... |
| CVE-2025-45542 | HIGH | 7.3 | 1.0% | Jun 2, 2025 | SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v... |
| CVE-2025-26396 | HIGH | 7.8 | 0.2% | Jun 2, 2025 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal... |
| CVE-2025-48990 | HIGH | 8.6 | 0.2% | Jun 2, 2025 | NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`,... |
| CVE-2025-48957 | HIGH | 7.5 | 0.6% | Jun 2, 2025 | AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions ... |
| CVE-2025-46807 | HIGH | 8.7 | 0.4% | Jun 2, 2025 | A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file... |
| CVE-2025-29785 | HIGH | 7.5 | 0.4% | Jun 2, 2025 | quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i... |
| CVE-2025-1246 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D... |
| CVE-2025-0819 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2025-0073 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-5440 | HIGH | 8.8 | 8.1% | Jun 2, 2025 | A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now