2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49251 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49180 | HIGH | 7.8 | 0.3% | Jun 17, 2025 | A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. T... |
| CVE-2025-49179 | HIGH | 7.3 | 0.3% | Jun 17, 2025 | A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer ... |
| CVE-2025-49176 | HIGH | 7.3 | 0.3% | Jun 17, 2025 | A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximu... |
| CVE-2025-48333 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - Wo... |
| CVE-2025-48274 | HIGH | 7.5 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job... |
| CVE-2025-48145 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Tr... |
| CVE-2025-48118 | HIGH | 8.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Wooc... |
| CVE-2025-47572 | HIGH | 7.5 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39508 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Cor... |
| CVE-2025-39486 | HIGH | 8.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie ... |
| CVE-2025-32549 | HIGH | 7.5 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30988 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ El... |
| CVE-2025-30562 | HIGH | 8.5 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navig... |
| CVE-2025-29002 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28991 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28972 | HIGH | 7.6 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Suhas Surse WP Emp... |
| CVE-2025-24761 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-4879 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2025-0320 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Win... |
| CVE-2025-6020 | HIGH | 7.8 | 0.4% | Jun 17, 2025 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, ... |
| CVE-2025-5777 | HIGH | 7.5 | 100.0% | Jun 17, 2025 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual serv... |
| CVE-2025-5349 | HIGH | 8.8 | 3.7% | Jun 17, 2025 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway |
| CVE-2025-4365 | HIGH | 7.5 | 7.0% | Jun 17, 2025 | Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) |
| CVE-2025-6173 | HIGH | 7.2 | 0.5% | Jun 17, 2025 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now