2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23968 | CRITICAL | 9.1 | 0.4% | Jul 3, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Uploa... |
| CVE-2025-6926 | HIGH | 8.8 | 0.4% | Jul 3, 2025 | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authenti... |
| CVE-2025-6074 | MEDIUM | 6.5 | 0.2% | Jul 3, 2025 | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enable... |
| CVE-2025-6073 | HIGH | 8.2 | 0.4% | Jul 3, 2025 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the u... |
| CVE-2025-6072 | HIGH | 8.2 | 0.3% | Jul 3, 2025 | Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the... |
| CVE-2025-6071 | MEDIUM | 6.3 | 0.2% | Jul 3, 2025 | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to sal... |
| CVE-2025-53502 | MEDIUM | 6.5 | 0.2% | Jul 3, 2025 | Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Sc... |
| CVE-2025-53501 | HIGH | 8.8 | 0.3% | Jul 3, 2025 | Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functio... |
| CVE-2025-53500 | MEDIUM | 5.6 | 0.2% | Jul 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53489 | MEDIUM | 5.6 | 0.2% | Jul 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-49846 | MEDIUM | 4.1 | 0.1% | Jul 3, 2025 | wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages t... |
| CVE-2025-48939 | MEDIUM | 4.2 | 0.2% | Jul 3, 2025 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in... |
| CVE-2025-53490 | MEDIUM | 5.6 | 0.2% | Jul 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-45938 | MEDIUM | 5.4 | 0.2% | Jul 3, 2025 | Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName paramete... |
| CVE-2025-5961 | HIGH | 7.2 | 6.5% | Jul 3, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads... |
| CVE-2025-50263 | HIGH | 8.1 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter. |
| CVE-2025-50262 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter. |
| CVE-2025-50260 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn para... |
| CVE-2025-50258 | HIGH | 8.1 | 0.4% | Jul 3, 2025 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter. |
| CVE-2025-43713 | MEDIUM | 6.5 | 0.4% | Jul 3, 2025 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows ... |
| CVE-2025-49618 | MEDIUM | 5.8 | 0.3% | Jul 3, 2025 | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, reg... |
| CVE-2025-49595 | MEDIUM | 4.9 | 0.4% | Jul 3, 2025 | n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/bina... |
| CVE-2025-49032 | MEDIUM | 6.5 | 0.2% | Jul 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Guten... |
| CVE-2025-3702 | MEDIUM | 5.4 | 0.2% | Jul 3, 2025 | Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting I... |
| CVE-2025-2932 | HIGH | 8.8 | 0.7% | Jul 3, 2025 | The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now