2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47943 | MEDIUM | 6.3 | 0.3% | Jun 24, 2025 | Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-sit... |
| CVE-2025-6552 | MEDIUM | 4.3 | 0.4% | Jun 24, 2025 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the functio... |
| CVE-2025-48470 | MEDIUM | 4.1 | 0.2% | Jun 24, 2025 | Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scr... |
| CVE-2025-48468 | MEDIUM | 6.4 | 0.2% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to ... |
| CVE-2025-48467 | MEDIUM | 6.5 | 0.2% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to r... |
| CVE-2025-48462 | MEDIUM | 4.2 | 0.2% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block ot... |
| CVE-2025-48461 | MEDIUM | 5 | 0.4% | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and... |
| CVE-2025-6551 | MEDIUM | 5.4 | 0.4% | Jun 24, 2025 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function ... |
| CVE-2025-6534 | MEDIUM | 6.8 | 0.4% | Jun 24, 2025 | A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affect... |
| CVE-2025-34032 | MEDIUM | 6.1 | 0.6% | Jun 24, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the ... |
| CVE-2025-6533 | MEDIUM | 5.9 | 0.5% | Jun 24, 2025 | A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected ... |
| CVE-2025-6532 | MEDIUM | 4.3 | 0.4% | Jun 24, 2025 | A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili... |
| CVE-2025-6531 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability ... |
| CVE-2025-6530 | MEDIUM | 4.8 | 0.5% | Jun 23, 2025 | A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown p... |
| CVE-2025-6528 | MEDIUM | 4.3 | 0.6% | Jun 23, 2025 | A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerabilit... |
| CVE-2025-6526 | MEDIUM | 5.3 | 0.5% | Jun 23, 2025 | A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects so... |
| CVE-2025-6525 | MEDIUM | 4.3 | 0.2% | Jun 23, 2025 | A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code ... |
| CVE-2025-52561 | MEDIUM | 6.9 | 0.7% | Jun 23, 2025 | HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist... |
| CVE-2025-49574 | MEDIUM | 6.4 | 0.3% | Jun 23, 2025 | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1,... |
| CVE-2025-6518 | MEDIUM | 6.3 | 0.3% | Jun 23, 2025 | A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the functio... |
| CVE-2025-52967 | MEDIUM | 5.8 | 0.4% | Jun 23, 2025 | gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation. |
| CVE-2025-52879 | MEDIUM | 4.8 | 0.9% | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible |
| CVE-2025-52878 | MEDIUM | 4.3 | 0.3% | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions |
| CVE-2025-52877 | MEDIUM | 4.8 | 13.5% | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible |
| CVE-2025-52876 | MEDIUM | 5.4 | 13.6% | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now