2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3780 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2025-47120 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co... |
| CVE-2025-47119 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could... |
| CVE-2025-49547 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-49534 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-49525 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-49524 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead... |
| CVE-2025-30313 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-27165 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-7031 | MEDIUM | 5.3 | 0.3% | Jul 8, 2025 | Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly C... |
| CVE-2025-7030 | MEDIUM | 6.5 | 0.4% | Jul 8, 2025 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrec... |
| CVE-2025-49545 | MEDIUM | 6.2 | 0.4% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabil... |
| CVE-2025-49544 | MEDIUM | 6.8 | 0.6% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-49543 | MEDIUM | 4.3 | 0.7% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili... |
| CVE-2025-49542 | MEDIUM | 5.2 | 1.1% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerab... |
| CVE-2025-49541 | MEDIUM | 4.3 | 0.7% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili... |
| CVE-2025-49540 | MEDIUM | 4.3 | 0.7% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili... |
| CVE-2025-49539 | MEDIUM | 4.5 | 0.5% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-43584 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2025-43583 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ... |
| CVE-2025-48386 | MEDIUM | 6.3 | 0.3% | Jul 8, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2025-27369 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a ... |
| CVE-2025-27367 | MEDIUM | 6.5 | 0.2% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side v... |
| CVE-2025-7363 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User i... |
| CVE-2025-7362 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now