2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4799 | HIGH | 7.2 | 0.8% | Jun 11, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d... |
| CVE-2025-4798 | MEDIUM | 4.9 | 0.4% | Jun 11, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1... |
| CVE-2025-4666 | MEDIUM | 6.4 | 0.3% | Jun 11, 2025 | The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versi... |
| CVE-2025-49793 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49792 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49791 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49790 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49789 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49788 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49787 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49786 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-49785 | — | — | — | Jun 11, 2025 | Rejected reason: Not used |
| CVE-2025-5959 | HIGH | 8.8 | 10.2% | Jun 11, 2025 | Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2025-5958 | HIGH | 8.8 | 0.4% | Jun 11, 2025 | Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-4275 | HIGH | 7.8 | 0.4% | Jun 11, 2025 | A vulnerability in the digital signature verification process does not properly validate variable attributes which allow... |
| CVE-2025-49091 | HIGH | 8.2 | 0.6% | Jun 11, 2025 | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme ... |
| CVE-2025-32717 | HIGH | 8.4 | 0.5% | Jun 11, 2025 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-30675 | MEDIUM | 4.7 | 0.6% | Jun 11, 2025 | In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or ... |
| CVE-2025-1055 | MEDIUM | 5.6 | 0.2% | Jun 11, 2025 | A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use... |
| CVE-2025-5985 | HIGH | 7.3 | 0.5% | Jun 10, 2025 | A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this i... |
| CVE-2025-5984 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe... |
| CVE-2025-47849 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do... |
| CVE-2025-47713 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do... |
| CVE-2025-47117 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47116 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now