2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6444 | MEDIUM | 5.9 | 0.4% | Jun 25, 2025 | ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-5833 | MEDIUM | 6.8 | 0.2% | Jun 25, 2025 | Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability a... |
| CVE-2025-5832 | MEDIUM | 6.8 | 0.2% | Jun 25, 2025 | Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnera... |
| CVE-2025-5829 | MEDIUM | 6.8 | 0.3% | Jun 25, 2025 | Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This... |
| CVE-2025-5828 | MEDIUM | 6.8 | 0.3% | Jun 25, 2025 | Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-5826 | MEDIUM | 6.3 | 0.2% | Jun 25, 2025 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerabili... |
| CVE-2025-5823 | MEDIUM | 6.5 | 0.5% | Jun 25, 2025 | Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. Thi... |
| CVE-2025-49550 | MEDIUM | 4.3 | 0.3% | Jun 25, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author... |
| CVE-2025-6442 | MEDIUM | 5.9 | 0.4% | Jun 25, 2025 | Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arb... |
| CVE-2025-52893 | MEDIUM | 4.5 | 0.3% | Jun 25, 2025 | OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi... |
| CVE-2025-52576 | MEDIUM | 5.3 | 0.3% | Jun 25, 2025 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vul... |
| CVE-2025-52569 | MEDIUM | 6.6 | 0.4% | Jun 25, 2025 | GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of i... |
| CVE-2025-50179 | MEDIUM | 4.3 | 0.1% | Jun 25, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a... |
| CVE-2025-50178 | MEDIUM | 6.6 | 0.4% | Jun 25, 2025 | GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for ... |
| CVE-2025-44206 | MEDIUM | 4.6 | 0.2% | Jun 25, 2025 | Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2... |
| CVE-2025-20264 | MEDIUM | 6.4 | 0.3% | Jun 25, 2025 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2025-49135 | MEDIUM | 6.5 | 0.3% | Jun 25, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 ha... |
| CVE-2025-48991 | MEDIUM | 4.3 | 0.1% | Jun 25, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a... |
| CVE-2025-48954 | MEDIUM | 6.1 | 0.6% | Jun 25, 2025 | Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh... |
| CVE-2025-25012 | MEDIUM | 5.4 | 0.4% | Jun 25, 2025 | URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and ser... |
| CVE-2025-6603 | MEDIUM | 5.3 | 0.1% | Jun 25, 2025 | A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as pro... |
| CVE-2025-6613 | MEDIUM | 5.4 | 0.3% | Jun 25, 2025 | A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulne... |
| CVE-2025-41647 | MEDIUM | 5.5 | 0.1% | Jun 25, 2025 | A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorre... |
| CVE-2025-43880 | MEDIUM | 5.3 | 0.3% | Jun 25, 2025 | Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may caus... |
| CVE-2025-5585 | MEDIUM | 5.4 | 0.2% | Jun 25, 2025 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now