2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49586 | HIGH | 8.8 | 0.6% | Jun 13, 2025 | XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic... |
| CVE-2025-49585 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10... |
| CVE-2025-49584 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.... |
| CVE-2025-49583 | LOW | 3.5 | 0.2% | Jun 13, 2025 | XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.... |
| CVE-2025-49582 | HIGH | 8 | 0.7% | Jun 13, 2025 | XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros tha... |
| CVE-2025-6052 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, co... |
| CVE-2025-6035 | MEDIUM | 6.1 | 0.4% | Jun 13, 2025 | A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs du... |
| CVE-2025-49581 | HIGH | 8.8 | 0.5% | Jun 13, 2025 | XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Gro... |
| CVE-2025-49580 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or pr... |
| CVE-2025-48920 | HIGH | 7.3 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker al... |
| CVE-2025-48919 | MEDIUM | 5 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar... |
| CVE-2025-48918 | HIGH | 8.8 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar... |
| CVE-2025-48917 | MEDIUM | 5 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie C... |
| CVE-2025-48916 | MEDIUM | 6.5 | 0.2% | Jun 13, 2025 | Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Cal... |
| CVE-2025-48915 | HIGH | 8.6 | 0.3% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-48914 | HIGH | 8.6 | 0.3% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-6030 | CRITICAL | 9.4 | 0.2% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyc... |
| CVE-2025-6029 | CRITICAL | 9.4 | 0.6% | Jun 13, 2025 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-br... |
| CVE-2025-36633 | HIGH | 7.8 | 0.2% | Jun 13, 2025 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrari... |
| CVE-2025-36631 | HIGH | 7.8 | 0.2% | Jun 13, 2025 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite... |
| CVE-2025-28389 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. |
| CVE-2025-28388 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. |
| CVE-2025-28386 | CRITICAL | 9.8 | 0.9% | Jun 13, 2025 | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers ... |
| CVE-2025-28384 | CRITICAL | 9.1 | 0.9% | Jun 13, 2025 | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory trav... |
| CVE-2025-28382 | HIGH | 7.5 | 0.9% | Jun 13, 2025 | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now