2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49845 | HIGH | 7.5 | 0.3% | Jun 25, 2025 | Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers... |
| CVE-2025-25905 | HIGH | 7.1 | 0.4% | Jun 25, 2025 | Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web ... |
| CVE-2025-6610 | HIGH | 7.2 | 0.3% | Jun 25, 2025 | A vulnerability was found in itsourcecode Employee Management System up to 1.0. It has been classified as critical. This... |
| CVE-2025-6609 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by thi... |
| CVE-2025-6608 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected b... |
| CVE-2025-6607 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affecte... |
| CVE-2025-6606 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Th... |
| CVE-2025-6605 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability ... |
| CVE-2025-6604 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects a... |
| CVE-2025-5927 | HIGH | 7.5 | 0.6% | Jun 25, 2025 | The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali... |
| CVE-2025-49797 | HIGH | 8.5 | 0.1% | Jun 25, 2025 | Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary ... |
| CVE-2025-41256 | HIGH | 7.4 | 0.1% | Jun 25, 2025 | Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), sinc... |
| CVE-2025-41255 | HIGH | 8 | 0.2% | Jun 25, 2025 | Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), un... |
| CVE-2025-36004 | HIGH | 8.8 | 0.5% | Jun 25, 2025 | IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Fa... |
| CVE-2025-0966 | HIGH | 7.6 | 0.3% | Jun 25, 2025 | IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL s... |
| CVE-2025-6583 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This af... |
| CVE-2025-6582 | HIGH | 8.8 | 0.4% | Jun 25, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Af... |
| CVE-2025-6581 | HIGH | 8.8 | 0.4% | Jun 24, 2025 | A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vu... |
| CVE-2025-52888 | HIGH | 7.5 | 0.3% | Jun 24, 2025 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entit... |
| CVE-2025-52882 | HIGH | 8.8 | 0.3% | Jun 24, 2025 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium)... |
| CVE-2025-49852 | HIGH | 8.7 | 0.4% | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability... |
| CVE-2025-6570 | HIGH | 8.8 | 0.4% | Jun 24, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected... |
| CVE-2025-44531 | HIGH | 7.5 | 0.4% | Jun 24, 2025 | An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a... |
| CVE-2025-23265 | HIGH | 7.8 | 0.3% | Jun 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i... |
| CVE-2025-23264 | HIGH | 7.8 | 0.3% | Jun 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now