2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46548 | MEDIUM | 6.5 | 0.7% | Jun 3, 2025 | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied... |
| CVE-2025-43925 | MEDIUM | 4.6 | 0.1% | Jun 3, 2025 | An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to... |
| CVE-2025-43924 | MEDIUM | 6.1 | 0.2% | Jun 3, 2025 | Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (f... |
| CVE-2025-43923 | MEDIUM | 6.5 | 0.2% | Jun 3, 2025 | An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Foca... |
| CVE-2025-36564 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal... |
| CVE-2025-5502 | CRITICAL | 9.8 | 7.6% | Jun 3, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this... |
| CVE-2025-5501 | MEDIUM | 6.9 | 0.6% | Jun 3, 2025 | A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi... |
| CVE-2025-5499 | CRITICAL | 9.8 | 0.6% | Jun 3, 2025 | A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function ... |
| CVE-2025-5498 | HIGH | 7.2 | 0.4% | Jun 3, 2025 | A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the... |
| CVE-2025-46154 | HIGH | 8.4 | 0.2% | Jun 3, 2025 | Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php. |
| CVE-2025-45855 | MEDIUM | 5.4 | 0.3% | Jun 3, 2025 | An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers t... |
| CVE-2025-5497 | CRITICAL | 9.8 | 0.5% | Jun 3, 2025 | A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the... |
| CVE-2025-5495 | CRITICAL | 9.8 | 0.8% | Jun 3, 2025 | A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow... |
| CVE-2025-4517 | CRITICAL | 9.4 | 1.2% | Jun 3, 2025 | Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe... |
| CVE-2025-4435 | HIGH | 7.5 | 0.5% | Jun 3, 2025 | When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members wo... |
| CVE-2025-4330 | HIGH | 7.5 | 0.8% | Jun 3, 2025 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the... |
| CVE-2025-4138 | HIGH | 7.5 | 1.1% | Jun 3, 2025 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the... |
| CVE-2025-5340 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’... |
| CVE-2025-4671 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and com... |
| CVE-2025-4205 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all ver... |
| CVE-2025-5493 | CRITICAL | 9.8 | 0.4% | Jun 3, 2025 | A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue ... |
| CVE-2025-5492 | HIGH | 8.8 | 2.9% | Jun 3, 2025 | A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnera... |
| CVE-2025-4392 | HIGH | 7.2 | 0.3% | Jun 3, 2025 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2025-31359 | HIGH | 8.8 | 1.7% | Jun 3, 2025 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers... |
| CVE-2025-5116 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ paramete... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now