2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49979 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-49978 | MEDIUM | 4.3 | 0.3% | Jun 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorr... |
| CVE-2025-49977 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross S... |
| CVE-2025-49976 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-49975 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss... |
| CVE-2025-49974 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allow... |
| CVE-2025-49973 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Siz... |
| CVE-2025-49972 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Reques... |
| CVE-2025-49971 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting ... |
| CVE-2025-49970 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Confi... |
| CVE-2025-49969 | MEDIUM | 4.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured A... |
| CVE-2025-49968 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cros... |
| CVE-2025-49967 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allo... |
| CVE-2025-49966 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API o... |
| CVE-2025-49965 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-c... |
| CVE-2025-49964 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issu... |
| CVE-2025-49873 | HIGH | 7.1 | 0.2% | Jun 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi e... |
| CVE-2025-46179 | CRITICAL | 9.8 | 0.5% | Jun 20, 2025 | A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx pa... |
| CVE-2025-3319 | CRITICAL | 9.8 | 0.3% | Jun 20, 2025 | IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session aut... |
| CVE-2025-3228 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-3227 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-6344 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulne... |
| CVE-2025-6343 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unkn... |
| CVE-2025-6342 | CRITICAL | 9.8 | 0.4% | Jun 20, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue aff... |
| CVE-2025-48706 | CRITICAL | 9.1 | 0.5% | Jun 20, 2025 | An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now