2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58707 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58705 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58024 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53440 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53346 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2025-53345 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress ... |
| CVE-2025-53302 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constraine... |
| CVE-2025-53209 | CRITICAL | 9.8 | 0.3% | Jun 2, 2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff... |
| CVE-2025-52766 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-52759 | HIGH | 7.1 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco... |
| CVE-2025-5085 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al... |
| CVE-2025-59614 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. |
| CVE-2025-59613 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
| CVE-2025-59612 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory corruption in windows drivers while sending incorrect trusted application request |
| CVE-2025-59611 | MEDIUM | 6.7 | 0.1% | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation |
| CVE-2025-59610 | MEDIUM | 6.4 | 0.1% | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa... |
| CVE-2025-59609 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. |
| CVE-2025-59606 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi... |
| CVE-2025-59605 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. |
| CVE-2025-59604 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
| CVE-2025-59601 | MEDIUM | 6.5 | 0.1% | Jun 1, 2026 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized... |
| CVE-2025-48652 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in... |
| CVE-2025-48649 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass... |
| CVE-2025-48648 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou... |
| CVE-2025-48616 | LOW | 3.3 | 0.1% | Jun 1, 2026 | In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now