2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49842 | LOW | 1 | 0.2% | Jun 17, 2025 | conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2... |
| CVE-2025-0320 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Win... |
| CVE-2025-6020 | HIGH | 7.8 | 0.4% | Jun 17, 2025 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, ... |
| CVE-2025-5777 | HIGH | 7.5 | 100.0% | Jun 17, 2025 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual serv... |
| CVE-2025-5349 | HIGH | 8.8 | 3.7% | Jun 17, 2025 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway |
| CVE-2025-4365 | HIGH | 7.5 | 7.0% | Jun 17, 2025 | Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) |
| CVE-2025-5700 | MEDIUM | 6.4 | 0.2% | Jun 17, 2025 | The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all... |
| CVE-2025-5291 | MEDIUM | 5.4 | 0.2% | Jun 17, 2025 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-3880 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-6050 | MEDIUM | 4.8 | 0.3% | Jun 17, 2025 | Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin inter... |
| CVE-2025-3515 | CRITICAL | 9.8 | 5.1% | Jun 17, 2025 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads d... |
| CVE-2025-40674 | MEDIUM | 5.1 | 0.4% | Jun 17, 2025 | Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code ... |
| CVE-2025-6173 | HIGH | 7.2 | 0.5% | Jun 17, 2025 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown f... |
| CVE-2025-6167 | CRITICAL | 9.8 | 0.7% | Jun 17, 2025 | A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function ... |
| CVE-2025-6166 | MEDIUM | 5.1 | 0.5% | Jun 17, 2025 | A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the func... |
| CVE-2025-6165 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability aff... |
| CVE-2025-6164 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an u... |
| CVE-2025-5209 | MEDIUM | 4.8 | 0.2% | Jun 17, 2025 | The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2025-6163 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is... |
| CVE-2025-6162 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this v... |
| CVE-2025-6161 | CRITICAL | 9.8 | 0.6% | Jun 17, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected... |
| CVE-2025-6160 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.... |
| CVE-2025-6159 | CRITICAL | 9.8 | 0.4% | Jun 17, 2025 | A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affec... |
| CVE-2025-6158 | HIGH | 8.8 | 0.8% | Jun 17, 2025 | A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the ... |
| CVE-2025-3494 | — | — | — | Jun 17, 2025 | Rejected reason: This CVE ID has been rejected by its CNA as it was not a security issue. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now