2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6818 | HIGH | 7.8 | 0.2% | Jun 28, 2025 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_prot... |
| CVE-2025-1991 | HIGH | 7.5 | 0.4% | Jun 28, 2025 | IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an in... |
| CVE-2025-6817 | LOW | 3.3 | 0.2% | Jun 28, 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C... |
| CVE-2025-6816 | LOW | 3.3 | 0.2% | Jun 28, 2025 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_... |
| CVE-2025-5937 | MEDIUM | 4.3 | 0.2% | Jun 28, 2025 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable ... |
| CVE-2025-38086 | MEDIUM | 5.5 | 0.2% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nw... |
| CVE-2025-38085 | MEDIUM | 4.7 | 0.1% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race... |
| CVE-2025-38084 | MEDIUM | 5.5 | 0.2% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, n... |
| CVE-2025-6755 | HIGH | 8.8 | 0.7% | Jun 28, 2025 | The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2025-5304 | CRITICAL | 9.8 | 0.6% | Jun 28, 2025 | The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ... |
| CVE-2025-6252 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ... |
| CVE-2025-6381 | HIGH | 8.8 | 0.7% | Jun 28, 2025 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including... |
| CVE-2025-6379 | HIGH | 8.8 | 0.7% | Jun 28, 2025 | The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2025-6350 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-53388 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53387 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53386 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53385 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53384 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53383 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53382 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53381 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-53380 | — | — | — | Jun 28, 2025 | Rejected reason: Not used |
| CVE-2025-36027 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By pe... |
| CVE-2025-36026 | MEDIUM | 4.3 | 0.1% | Jun 28, 2025 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Atta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now