2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49487 | MEDIUM | 6.8 | 0.2% | Jun 17, 2025 | An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could h... |
| CVE-2025-49158 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc... |
| CVE-2025-49157 | HIGH | 7.8 | 0.2% | Jun 17, 2025 | A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalat... |
| CVE-2025-49156 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privil... |
| CVE-2025-49155 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacke... |
| CVE-2025-49154 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allo... |
| CVE-2025-34511 | HIGH | 8.8 | 8.5% | Jun 17, 2025 | Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through vers... |
| CVE-2025-34510 | HIGH | 8.8 | 9.2% | Jun 17, 2025 | Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10... |
| CVE-2025-34509 | HIGH | 7.5 | 38.4% | Jun 17, 2025 | Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 1... |
| CVE-2025-49220 | CRITICAL | 9.8 | 1.9% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat... |
| CVE-2025-49219 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica... |
| CVE-2025-47867 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta... |
| CVE-2025-47866 | HIGH | 7.5 | 0.2% | Jun 17, 2025 | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att... |
| CVE-2025-47865 | CRITICAL | 9.8 | 1.2% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker... |
| CVE-2025-33122 | HIGH | 7.5 | 0.3% | Jun 17, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in I... |
| CVE-2025-45880 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows a... |
| CVE-2025-45878 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers t... |
| CVE-2025-45879 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers t... |
| CVE-2025-6199 | LOW | 3.3 | 0.1% | Jun 17, 2025 | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio... |
| CVE-2025-6196 | MEDIUM | 5.5 | 0.2% | Jun 17, 2025 | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when ope... |
| CVE-2025-4754 | LOW | 2.3 | 0.4% | Jun 17, 2025 | Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This v... |
| CVE-2025-49882 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer Cube... |
| CVE-2025-49881 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-49880 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ... |
| CVE-2025-49879 | HIGH | 8.6 | 0.4% | Jun 17, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now