2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7785 | MEDIUM | 4.3 | 0.4% | Jul 18, 2025 | A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the fun... |
| CVE-2025-6227 | LOW | 3.1 | 0.2% | Jul 18, 2025 | Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al... |
| CVE-2025-6233 | MEDIUM | 4.9 | 0.4% | Jul 18, 2025 | Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths... |
| CVE-2025-50126 | MEDIUM | 5.3 | 0.3% | Jul 18, 2025 | A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authent... |
| CVE-2025-50058 | MEDIUM | 5.1 | 0.4% | Jul 18, 2025 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote auth... |
| CVE-2025-50057 | MEDIUM | 6.9 | 0.4% | Jul 18, 2025 | A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote a... |
| CVE-2025-50056 | MEDIUM | 5.1 | 0.4% | Jul 18, 2025 | A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote a... |
| CVE-2025-49486 | HIGH | 8.6 | 0.3% | Jul 18, 2025 | A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicio... |
| CVE-2025-49485 | HIGH | 8.6 | 0.3% | Jul 18, 2025 | A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute ar... |
| CVE-2025-49484 | HIGH | 8.7 | 3.1% | Jul 18, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execut... |
| CVE-2025-2425 | MEDIUM | 5.1 | 0.1% | Jul 18, 2025 | Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET secu... |
| CVE-2025-7444 | CRITICAL | 9.8 | 0.5% | Jul 18, 2025 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0... |
| CVE-2025-6226 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization... |
| CVE-2025-6197 | MEDIUM | 4.2 | 3.7% | Jul 18, 2025 | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites ... |
| CVE-2025-6023 | HIGH | 7.6 | 37.6% | Jul 18, 2025 | An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln... |
| CVE-2025-38349 | HIGH | 7.8 | 0.2% | Jul 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still ... |
| CVE-2025-26855 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL c... |
| CVE-2025-26854 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQ... |
| CVE-2025-7772 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F... |
| CVE-2025-7438 | HIGH | 7.5 | 0.6% | Jul 18, 2025 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid... |
| CVE-2025-7643 | CRITICAL | 9.1 | 0.7% | Jul 18, 2025 | The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-6726 | MEDIUM | 4.3 | 0.2% | Jul 18, 2025 | The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2025-6719 | MEDIUM | 4.4 | 0.2% | Jul 18, 2025 | The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-6718 | HIGH | 8.8 | 0.3% | Jul 18, 2025 | The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX... |
| CVE-2025-6717 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now