2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43585 | HIGH | 8.2 | 0.4% | Jun 10, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authori... |
| CVE-2025-40591 | HIGH | 8.3 | 1.3% | Jun 10, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-40567 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532... |
| CVE-2025-5353 | HIGH | 7.8 | 0.3% | Jun 10, 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt s... |
| CVE-2025-5335 | HIGH | 7.8 | 0.2% | Jun 10, 2025 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a... |
| CVE-2025-46612 | HIGH | 7.2 | 0.6% | Jun 10, 2025 | The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary comma... |
| CVE-2025-37100 | HIGH | 7.7 | 0.4% | Jun 10, 2025 | A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to un... |
| CVE-2025-30145 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be ... |
| CVE-2025-22463 | HIGH | 7.3 | 0.3% | Jun 10, 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt t... |
| CVE-2025-22455 | HIGH | 7.8 | 0.3% | Jun 10, 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt st... |
| CVE-2025-49511 | HIGH | 7.1 | 0.2% | Jun 10, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery... |
| CVE-2025-49454 | HIGH | 8.1 | 0.5% | Jun 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-43701 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settin... |
| CVE-2025-43700 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted dat... |
| CVE-2025-43697 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted da... |
| CVE-2025-40662 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents... |
| CVE-2025-40661 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40660 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40659 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-40658 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows... |
| CVE-2025-5743 | HIGH | 7 | 0.9% | Jun 10, 2025 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2025-5740 | HIGH | 8.6 | 0.6% | Jun 10, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-4681 | HIGH | 8.6 | 0.2% | Jun 10, 2025 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abu... |
| CVE-2025-4680 | HIGH | 8.6 | 0.2% | Jun 10, 2025 | Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorr... |
| CVE-2025-3898 | HIGH | 7.1 | 0.4% | Jun 10, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now