2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5439 | HIGH | 8.8 | 8.1% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-3260 | HIGH | 8.3 | 0.5% | Jun 2, 2025 | A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a... |
| CVE-2025-5455 | HIGH | 8.4 | 0.3% | Jun 2, 2025 | An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkRe... |
| CVE-2025-5438 | HIGH | 8.8 | 31.1% | Jun 2, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-5435 | HIGH | 7.3 | 0.4% | Jun 2, 2025 | A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unkno... |
| CVE-2025-5113 | HIGH | 8.6 | 6.8% | Jun 2, 2025 | The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and ... |
| CVE-2025-0358 | HIGH | 8.8 | 0.2% | Jun 2, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi... |
| CVE-2025-0324 | HIGH | 8.8 | 0.3% | Jun 2, 2025 | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain admini... |
| CVE-2025-5434 | HIGH | 7.3 | 0.3% | Jun 2, 2025 | A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown pa... |
| CVE-2025-4010 | HIGH | 8.6 | 0.6% | Jun 2, 2025 | The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoin... |
| CVE-2025-5431 | HIGH | 8.8 | 0.4% | Jun 2, 2025 | A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of th... |
| CVE-2025-49113 | HIGH | 8.8 | 89.5% | Jun 2, 2025 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the ... |
| CVE-2025-25179 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ... |
| CVE-2025-5406 | HIGH | 8.8 | 0.4% | Jun 1, 2025 | A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952... |
| CVE-2025-5404 | HIGH | 7.5 | 0.7% | Jun 1, 2025 | A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c673... |
| CVE-2025-5403 | HIGH | 8.8 | 0.4% | Jun 1, 2025 | A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6... |
| CVE-2025-33005 | HIGH | 8.8 | 0.2% | Jun 1, 2025 | IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated u... |
| CVE-2025-5381 | HIGH | 7.2 | 0.6% | May 31, 2025 | A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function down... |
| CVE-2025-4857 | HIGH | 7.2 | 0.6% | May 31, 2025 | The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9... |
| CVE-2025-5375 | HIGH | 8.8 | 0.2% | May 31, 2025 | A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critica... |
| CVE-2025-5374 | HIGH | 8.8 | 0.2% | May 31, 2025 | A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affec... |
| CVE-2025-5373 | HIGH | 8.8 | 0.2% | May 31, 2025 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulner... |
| CVE-2025-4672 | HIGH | 8.8 | 0.4% | May 31, 2025 | The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac... |
| CVE-2025-4103 | HIGH | 8.8 | 0.3% | May 31, 2025 | The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj... |
| CVE-2025-5368 | HIGH | 8.8 | 0.3% | May 31, 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now