2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40655 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40654 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-5743 | HIGH | 7 | 0.9% | Jun 10, 2025 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2025-5742 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a... |
| CVE-2025-5741 | MEDIUM | 6.9 | 0.5% | Jun 10, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-5740 | HIGH | 8.6 | 0.6% | Jun 10, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-4681 | HIGH | 8.6 | 0.2% | Jun 10, 2025 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abu... |
| CVE-2025-4680 | HIGH | 8.6 | 0.2% | Jun 10, 2025 | Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorr... |
| CVE-2025-3905 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact... |
| CVE-2025-3899 | MEDIUM | 5.4 | 0.1% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Cer... |
| CVE-2025-3898 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou... |
| CVE-2025-3117 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impact... |
| CVE-2025-3116 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou... |
| CVE-2025-3112 | HIGH | 7.1 | 0.5% | Jun 10, 2025 | CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated... |
| CVE-2025-5945 | — | — | — | Jun 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-27819 | HIGH | 7.5 | 0.9% | Jun 10, 2025 | In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Co... |
| CVE-2025-27818 | HIGH | 8.8 | 0.9% | Jun 10, 2025 | A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the clus... |
| CVE-2025-27817 | HIGH | 7.5 | 60.8% | Jun 10, 2025 | A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients a... |
| CVE-2025-4954 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenti... |
| CVE-2025-4840 | HIGH | 7.5 | 0.5% | Jun 10, 2025 | The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter b... |
| CVE-2025-1041 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v... |
| CVE-2025-5952 | HIGH | 7.3 | 1.9% | Jun 10, 2025 | A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the f... |
| CVE-2025-5935 | HIGH | 7.5 | 0.8% | Jun 10, 2025 | A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is... |
| CVE-2025-3076 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text... |
| CVE-2025-5934 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now