2025 CVE Vulnerabilities
45,259 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6236 | MEDIUM | 4.8 | 0.2% | Jul 10, 2025 | The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2025-6234 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2025-53753 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53752 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53751 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53750 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53749 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53748 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53747 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-53746 | — | — | — | Jul 10, 2025 | Rejected reason: Not used |
| CVE-2025-46406 | MEDIUM | 5.6 | 0.1% | Jul 10, 2025 | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l... |
| CVE-2025-44003 | MEDIUM | 4.3 | 0.2% | Jul 10, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ... |
| CVE-2025-35983 | MEDIUM | 6.5 | 0.2% | Jul 10, 2025 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta... |
| CVE-2025-5807 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param... |
| CVE-2025-4406 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2025-6976 | MEDIUM | 5.4 | 0.2% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-6975 | MEDIUM | 6.1 | 0.3% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2025-6970 | HIGH | 7.5 | 55.7% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2025-0646 | — | — | — | Jul 9, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-0141 | HIGH | 8.4 | 0.2% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authen... |
| CVE-2025-0140 | MEDIUM | 6.8 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0139 | MEDIUM | 6.3 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc... |
| CVE-2025-6377 | HIGH | 7.8 | 0.2% | Jul 9, 2025 | A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Sim... |
| CVE-2025-6376 | HIGH | 7.8 | 0.2% | Jul 9, 2025 | A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Sim... |
| CVE-2025-53624 | CRITICAL | 10 | 1.8% | Jul 9, 2025 | The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now