2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5964 | MEDIUM | 6.5 | 10.3% | Jun 15, 2025 | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to... |
| CVE-2025-6092 | MEDIUM | 4.3 | 0.3% | Jun 15, 2025 | A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this ... |
| CVE-2025-5990 | MEDIUM | 5.4 | 0.2% | Jun 15, 2025 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a ... |
| CVE-2025-6091 | HIGH | 8.8 | 0.5% | Jun 15, 2025 | A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function Upd... |
| CVE-2025-6090 | HIGH | 8.8 | 0.5% | Jun 15, 2025 | A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function Updat... |
| CVE-2025-22854 | MEDIUM | 6.9 | 0.3% | Jun 15, 2025 | Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal u... |
| CVE-2025-21085 | LOW | 2.1 | 0.3% | Jun 15, 2025 | PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory ut... |
| CVE-2025-6089 | MEDIUM | 6.1 | 0.3% | Jun 15, 2025 | A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability a... |
| CVE-2025-36041 | CRITICAL | 9.8 | 0.3% | Jun 15, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-1411 | HIGH | 7.8 | 0.1% | Jun 15, 2025 | IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root d... |
| CVE-2025-5337 | MEDIUM | 5.4 | 0.2% | Jun 14, 2025 | The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-5238 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter i... |
| CVE-2025-4667 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto... |
| CVE-2025-6070 | MEDIUM | 6.5 | 0.6% | Jun 14, 2025 | The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,... |
| CVE-2025-6065 | CRITICAL | 9.1 | 0.8% | Jun 14, 2025 | The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2025-6064 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-6063 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-6062 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-6061 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod... |
| CVE-2025-6055 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-6040 | MEDIUM | 6.1 | 0.2% | Jun 14, 2025 | The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-5589 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-cla... |
| CVE-2025-5336 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter i... |
| CVE-2025-4592 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2025-4216 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' short... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now