2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26394 | MEDIUM | 4.8 | 0.2% | Jun 10, 2025 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sani... |
| CVE-2025-22463 | HIGH | 7.3 | 0.3% | Jun 10, 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt t... |
| CVE-2025-22455 | HIGH | 7.8 | 0.3% | Jun 10, 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt st... |
| CVE-2025-49511 | HIGH | 7.1 | 0.2% | Jun 10, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery... |
| CVE-2025-49510 | MEDIUM | 4.3 | 0.1% | Jun 10, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce produc... |
| CVE-2025-49509 | MEDIUM | 5.3 | 0.3% | Jun 10, 2025 | Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting ... |
| CVE-2025-49507 | CRITICAL | 9.8 | 0.5% | Jun 10, 2025 | Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect... |
| CVE-2025-49455 | CRITICAL | 9.3 | 0.4% | Jun 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor... |
| CVE-2025-49454 | HIGH | 8.1 | 0.5% | Jun 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-4774 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow... |
| CVE-2025-4577 | MEDIUM | 5.4 | 0.3% | Jun 10, 2025 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-43701 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settin... |
| CVE-2025-43700 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted dat... |
| CVE-2025-43699 | MEDIUM | 5.3 | 0.4% | Jun 10, 2025 | Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of requ... |
| CVE-2025-43698 | CRITICAL | 9.1 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec... |
| CVE-2025-43697 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted da... |
| CVE-2025-2918 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mult... |
| CVE-2025-41657 | MEDIUM | 4.3 | 0.2% | Jun 10, 2025 | Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerpri... |
| CVE-2025-40662 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents... |
| CVE-2025-40661 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40660 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40659 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40658 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40657 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40656 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now