2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48444 | MEDIUM | 5.3 | 0.2% | Jun 11, 2025 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl... |
| CVE-2025-48013 | MEDIUM | 5.3 | 0.2% | Jun 11, 2025 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl... |
| CVE-2025-3473 | MEDIUM | 6.7 | 0.1% | Jun 11, 2025 | IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inhe... |
| CVE-2025-0163 | MEDIUM | 5.3 | 0.3% | Jun 11, 2025 | IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames... |
| CVE-2025-4922 | HIGH | 8.1 | 0.5% | Jun 11, 2025 | Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and... |
| CVE-2025-4605 | MEDIUM | 6.6 | 0.2% | Jun 11, 2025 | A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnera... |
| CVE-2025-40914 | CRITICAL | 9.8 | 0.4% | Jun 11, 2025 | Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a ... |
| CVE-2025-35941 | MEDIUM | 5.5 | 0.3% | Jun 11, 2025 | A password is exposed locally. |
| CVE-2025-32711 | HIGH | 7.5 | 5.8% | Jun 11, 2025 | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-5144 | MEDIUM | 5.4 | 0.2% | Jun 11, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ paramete... |
| CVE-2025-5986 | MEDIUM | 6.5 | 0.5% | Jun 11, 2025 | A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's de... |
| CVE-2025-5687 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M... |
| CVE-2025-49710 | CRITICAL | 9.8 | 0.7% | Jun 11, 2025 | An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir... |
| CVE-2025-49709 | CRITICAL | 9.8 | 0.6% | Jun 11, 2025 | Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. |
| CVE-2025-3302 | HIGH | 7.2 | 0.3% | Jun 11, 2025 | The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ ... |
| CVE-2025-4573 | MEDIUM | 4.1 | 0.2% | Jun 11, 2025 | Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LD... |
| CVE-2025-4128 | MEDIUM | 4.3 | 0.2% | Jun 11, 2025 | Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi... |
| CVE-2025-4315 | HIGH | 8.8 | 0.4% | Jun 11, 2025 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all vers... |
| CVE-2025-41663 | CRITICAL | 9.8 | 0.5% | Jun 11, 2025 | For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman... |
| CVE-2025-41662 | — | — | — | Jun 11, 2025 | Rejected reason: CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE ... |
| CVE-2025-41661 | HIGH | 8.8 | 0.3% | Jun 11, 2025 | An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack o... |
| CVE-2025-26412 | MEDIUM | 6.8 | 0.3% | Jun 11, 2025 | The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with ... |
| CVE-2025-5991 | LOW | 2.1 | 0.1% | Jun 11, 2025 | There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/... |
| CVE-2025-29756 | HIGH | 8.3 | 0.2% | Jun 11, 2025 | SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the us... |
| CVE-2025-5395 | HIGH | 8.8 | 0.6% | Jun 11, 2025 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now