2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58954 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions. |
| CVE-2025-58953 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions. |
| CVE-2025-58952 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions. |
| CVE-2025-58924 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Geya <= 1.15 versions. |
| CVE-2025-49403 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. |
| CVE-2025-48643 | HIGH | 7.8 | 0.1% | Jun 17, 2026 | In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local... |
| CVE-2025-48640 | HIGH | 8 | 0.1% | Jun 17, 2026 | In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T... |
| CVE-2025-48617 | HIGH | 7.8 | 0.1% | Jun 17, 2026 | In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. ... |
| CVE-2025-48571 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er... |
| CVE-2025-31013 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow... |
| CVE-2025-15642 | MEDIUM | 6.8 | 0.1% | Jun 17, 2026 | Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad... |
| CVE-2025-15641 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad... |
| CVE-2025-71261 | HIGH | 8.6 | 0.2% | Jun 16, 2026 | An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.... |
| CVE-2025-14272 | HIGH | 8.3 | 0.2% | Jun 16, 2026 | A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerabili... |
| CVE-2025-13036 | CRITICAL | 9.2 | 0.3% | Jun 16, 2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending request... |
| CVE-2025-11694 | HIGH | 8.7 | 0.2% | Jun 16, 2026 | A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and sourc... |
| CVE-2025-68045 | HIGH | 7.5 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. |
| CVE-2025-9912 | MEDIUM | 6.3 | 0.1% | Jun 16, 2026 | Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit... |
| CVE-2025-10262 | MEDIUM | 6.3 | 0.1% | Jun 16, 2026 | Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu... |
| CVE-2025-69332 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | Subscriber Broken Access Control in Bookify <= 1.1.1 versions. |
| CVE-2025-68872 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. |
| CVE-2025-68851 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. |
| CVE-2025-68840 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. |
| CVE-2025-68049 | MEDIUM | 6.3 | 0.2% | Jun 15, 2026 | Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. |
| CVE-2025-60175 | MEDIUM | 4.4 | 0.2% | Jun 15, 2026 | Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now