2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1411 | HIGH | 7.8 | 0.1% | Jun 15, 2025 | IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root d... |
| CVE-2025-4200 | HIGH | 8.1 | 0.6% | Jun 14, 2025 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusi... |
| CVE-2025-5487 | HIGH | 7.2 | 0.3% | Jun 14, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-3234 | HIGH | 7.2 | 0.5% | Jun 14, 2025 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2025-33108 | HIGH | 8.8 | 0.5% | Jun 14, 2025 | IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a... |
| CVE-2025-25215 | HIGH | 8.8 | 1.7% | Jun 13, 2025 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell... |
| CVE-2025-24919 | HIGH | 8.1 | 1.8% | Jun 13, 2025 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 p... |
| CVE-2025-25050 | HIGH | 8.8 | 1.4% | Jun 13, 2025 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior... |
| CVE-2025-24922 | HIGH | 8.8 | 2.2% | Jun 13, 2025 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior ... |
| CVE-2025-24311 | HIGH | 8.4 | 1.3% | Jun 13, 2025 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.1... |
| CVE-2025-49587 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifi... |
| CVE-2025-49586 | HIGH | 8.8 | 0.6% | Jun 13, 2025 | XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic... |
| CVE-2025-49585 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10... |
| CVE-2025-49584 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.... |
| CVE-2025-49582 | HIGH | 8 | 0.7% | Jun 13, 2025 | XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros tha... |
| CVE-2025-6052 | HIGH | 7.5 | 0.4% | Jun 13, 2025 | A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, co... |
| CVE-2025-49581 | HIGH | 8.8 | 0.5% | Jun 13, 2025 | XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Gro... |
| CVE-2025-49580 | HIGH | 8 | 0.4% | Jun 13, 2025 | XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or pr... |
| CVE-2025-48920 | HIGH | 7.3 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker al... |
| CVE-2025-48918 | HIGH | 8.8 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar... |
| CVE-2025-48915 | HIGH | 8.6 | 0.3% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-48914 | HIGH | 8.6 | 0.3% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-36633 | HIGH | 7.8 | 0.2% | Jun 13, 2025 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrari... |
| CVE-2025-36631 | HIGH | 7.8 | 0.2% | Jun 13, 2025 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite... |
| CVE-2025-28382 | HIGH | 7.5 | 0.9% | Jun 13, 2025 | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now