2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48447 | HIGH | 7.1 | 0.3% | Jun 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgaller... |
| CVE-2025-48446 | HIGH | 8.8 | 0.3% | Jun 11, 2025 | Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affec... |
| CVE-2025-48445 | HIGH | 8.8 | 0.3% | Jun 11, 2025 | Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affe... |
| CVE-2025-4922 | HIGH | 8.1 | 0.5% | Jun 11, 2025 | Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and... |
| CVE-2025-32711 | HIGH | 7.5 | 5.8% | Jun 11, 2025 | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-5687 | HIGH | 7.8 | 0.1% | Jun 11, 2025 | A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M... |
| CVE-2025-3302 | HIGH | 7.2 | 0.3% | Jun 11, 2025 | The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ ... |
| CVE-2025-4315 | HIGH | 8.8 | 0.4% | Jun 11, 2025 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all vers... |
| CVE-2025-41661 | HIGH | 8.8 | 0.3% | Jun 11, 2025 | An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack o... |
| CVE-2025-29756 | HIGH | 8.3 | 0.2% | Jun 11, 2025 | SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the us... |
| CVE-2025-5395 | HIGH | 8.8 | 0.6% | Jun 11, 2025 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ... |
| CVE-2025-4799 | HIGH | 7.2 | 0.8% | Jun 11, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d... |
| CVE-2025-5959 | HIGH | 8.8 | 10.2% | Jun 11, 2025 | Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2025-5958 | HIGH | 8.8 | 0.4% | Jun 11, 2025 | Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-4275 | HIGH | 7.8 | 0.4% | Jun 11, 2025 | A vulnerability in the digital signature verification process does not properly validate variable attributes which allow... |
| CVE-2025-49091 | HIGH | 8.2 | 0.6% | Jun 11, 2025 | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme ... |
| CVE-2025-32717 | HIGH | 8.4 | 0.5% | Jun 11, 2025 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-5985 | HIGH | 7.3 | 0.5% | Jun 10, 2025 | A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this i... |
| CVE-2025-47849 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do... |
| CVE-2025-47713 | HIGH | 8.8 | 0.5% | Jun 10, 2025 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do... |
| CVE-2025-46840 | HIGH | 8.7 | 0.4% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could ... |
| CVE-2025-46837 | HIGH | 8.7 | 0.4% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-26521 | HIGH | 8.1 | 0.6% | Jun 10, 2025 | When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret k... |
| CVE-2025-5978 | HIGH | 8.8 | 0.8% | Jun 10, 2025 | A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVir... |
| CVE-2025-35940 | HIGH | 8.1 | 0.3% | Jun 10, 2025 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can genera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now