2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4200 | HIGH | 8.1 | 0.6% | Jun 14, 2025 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusi... |
| CVE-2025-4187 | MEDIUM | 5.9 | 0.6% | Jun 14, 2025 | The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a... |
| CVE-2025-5487 | HIGH | 7.2 | 0.3% | Jun 14, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-3234 | HIGH | 7.2 | 0.5% | Jun 14, 2025 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2025-6059 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-50150 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50149 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50148 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50147 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50146 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50145 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50144 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50143 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-50142 | — | — | — | Jun 14, 2025 | Rejected reason: Not used |
| CVE-2025-33108 | HIGH | 8.8 | 0.5% | Jun 14, 2025 | IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a... |
| CVE-2025-25215 | HIGH | 8.8 | 1.7% | Jun 13, 2025 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell... |
| CVE-2025-24919 | HIGH | 8.1 | 1.8% | Jun 13, 2025 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 p... |
| CVE-2025-6083 | MEDIUM | 4.3 | 0.2% | Jun 13, 2025 | In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id fi... |
| CVE-2025-49598 | MEDIUM | 4.4 | 0.1% | Jun 13, 2025 | conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feed... |
| CVE-2025-25050 | HIGH | 8.8 | 1.4% | Jun 13, 2025 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior... |
| CVE-2025-24922 | HIGH | 8.8 | 2.2% | Jun 13, 2025 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior ... |
| CVE-2025-24311 | HIGH | 8.4 | 1.3% | Jun 13, 2025 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.1... |
| CVE-2025-49597 | LOW | 3.9 | 0.2% | Jun 13, 2025 | handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export libr... |
| CVE-2025-49596 | CRITICAL | 9.4 | 37.0% | Jun 13, 2025 | The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are ... |
| CVE-2025-49587 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now