2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4229 | MEDIUM | 6 | 0.4% | Jun 13, 2025 | An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor... |
| CVE-2025-4227 | LOW | 3.5 | 0.1% | Jun 13, 2025 | An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g... |
| CVE-2025-5815 | MEDIUM | 5.3 | 0.4% | Jun 13, 2025 | The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-5282 | HIGH | 7.5 | 0.3% | Jun 13, 2025 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l... |
| CVE-2025-5950 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versio... |
| CVE-2025-5939 | MEDIUM | 4.4 | 0.2% | Jun 13, 2025 | The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2025-5938 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request... |
| CVE-2025-5930 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2... |
| CVE-2025-5928 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up... |
| CVE-2025-5926 | MEDIUM | 6.1 | 0.1% | Jun 13, 2025 | The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0... |
| CVE-2025-5841 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all ver... |
| CVE-2025-5491 | HIGH | 8.8 | 0.6% | Jun 13, 2025 | Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a cu... |
| CVE-2025-5288 | CRITICAL | 9.8 | 0.5% | Jun 13, 2025 | The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri... |
| CVE-2025-5233 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versi... |
| CVE-2025-5123 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ p... |
| CVE-2025-4586 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' sh... |
| CVE-2025-4585 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode ... |
| CVE-2025-4584 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' short... |
| CVE-2025-47959 | HIGH | 7.1 | 5.4% | Jun 13, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize... |
| CVE-2025-30399 | HIGH | 7.5 | 0.9% | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2025-4232 | HIGH | 8.8 | 0.4% | Jun 13, 2025 | An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™... |
| CVE-2025-4231 | HIGH | 7.2 | 1.0% | Jun 13, 2025 | A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform ... |
| CVE-2025-4230 | HIGH | 8.4 | 0.6% | Jun 13, 2025 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas... |
| CVE-2025-4228 | MEDIUM | 4.6 | 0.2% | Jun 13, 2025 | An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated admi... |
| CVE-2025-4233 | MEDIUM | 5.1 | 0.2% | Jun 12, 2025 | An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now