2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6081 | MEDIUM | 6.8 | 0.3% | Jul 1, 2025 | Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earli... |
| CVE-2025-5967 | MEDIUM | 5.3 | 0.2% | Jul 1, 2025 | A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the E... |
| CVE-2025-53096 | MEDIUM | 6.1 | 0.2% | Jul 1, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks p... |
| CVE-2025-36056 | MEDIUM | 5.4 | 0.2% | Jul 1, 2025 | IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 ... |
| CVE-2025-2141 | MEDIUM | 6.1 | 0.2% | Jul 1, 2025 | IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 ... |
| CVE-2025-52996 | MEDIUM | 4.3 | 0.3% | Jun 30, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52995 | MEDIUM | 6.6 | 0.5% | Jun 30, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52901 | MEDIUM | 6.5 | 0.5% | Jun 30, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52491 | MEDIUM | 5.8 | 0.3% | Jun 30, 2025 | Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF. |
| CVE-2025-49493 | MEDIUM | 5.8 | 3.4% | Jun 30, 2025 | Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. |
| CVE-2025-52896 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could uploa... |
| CVE-2025-47871 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-46702 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-2895 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to... |
| CVE-2025-4407 | MEDIUM | 6.8 | 0.2% | Jun 30, 2025 | Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1. |
| CVE-2025-41439 | MEDIUM | 6.1 | 0.2% | Jun 30, 2025 | A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Strea... |
| CVE-2025-40734 | MEDIUM | 6.1 | 0.2% | Jun 30, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker ... |
| CVE-2025-40733 | MEDIUM | 6.1 | 0.2% | Jun 30, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker ... |
| CVE-2025-38090 | MEDIUM | 5.5 | 0.2% | Jun 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap ove... |
| CVE-2025-38089 | MEDIUM | 5.5 | 0.3% | Jun 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processi... |
| CVE-2025-5730 | MEDIUM | 4.3 | 0.2% | Jun 30, 2025 | The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could al... |
| CVE-2025-3745 | MEDIUM | 6.3 | 0.2% | Jun 30, 2025 | The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links ... |
| CVE-2025-6883 | MEDIUM | 6.3 | 0.3% | Jun 30, 2025 | A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unk... |
| CVE-2025-6870 | MEDIUM | 4.7 | 0.4% | Jun 29, 2025 | A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this ... |
| CVE-2025-24292 | MEDIUM | 6.8 | 0.3% | Jun 29, 2025 | A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VP... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now