2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6707 | MEDIUM | 5.4 | 0.1% | Jun 26, 2025 | Under certain conditions, an authenticated user request may execute with stale privileges following an intentional chang... |
| CVE-2025-6706 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior... |
| CVE-2025-6695 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown ... |
| CVE-2025-6694 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects ... |
| CVE-2025-6677 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs ... |
| CVE-2025-6676 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML ... |
| CVE-2025-6675 | MEDIUM | 4.8 | 0.2% | Jun 26, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
| CVE-2025-6674 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Y... |
| CVE-2025-5682 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki... |
| CVE-2025-52573 | MEDIUM | 6 | 0.7% | Jun 26, 2025 | iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulator... |
| CVE-2025-49003 | CRITICAL | 9.8 | 0.8% | Jun 26, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m... |
| CVE-2025-48923 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allo... |
| CVE-2025-48922 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox a... |
| CVE-2025-48921 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affec... |
| CVE-2025-6693 | HIGH | 8.5 | 0.2% | Jun 26, 2025 | A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_dev... |
| CVE-2025-6562 | HIGH | 8.8 | 0.9% | Jun 26, 2025 | Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow... |
| CVE-2025-5966 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by f... |
| CVE-2025-5366 | HIGH | 8.1 | 1.1% | Jun 26, 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read... |
| CVE-2025-6561 | CRITICAL | 9.8 | 0.5% | Jun 26, 2025 | Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne... |
| CVE-2025-3773 | MEDIUM | 5.5 | 0.1% | Jun 26, 2025 | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authentic... |
| CVE-2025-3771 | HIGH | 7.1 | 0.1% | Jun 26, 2025 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin loc... |
| CVE-2025-3722 | MEDIUM | 4.4 | 0.2% | Jun 26, 2025 | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privi... |
| CVE-2025-6703 | MEDIUM | 6.5 | 0.2% | Jun 26, 2025 | Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0... |
| CVE-2025-6212 | MEDIUM | 6.1 | 0.3% | Jun 26, 2025 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m... |
| CVE-2025-5842 | MEDIUM | 5.4 | 0.3% | Jun 26, 2025 | The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now