2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6866 | MEDIUM | 4.3 | 0.4% | Jun 29, 2025 | A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects ... |
| CVE-2025-6865 | MEDIUM | 4.3 | 0.2% | Jun 29, 2025 | A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of ... |
| CVE-2025-6864 | MEDIUM | 4.3 | 0.2% | Jun 29, 2025 | A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is som... |
| CVE-2025-6858 | MEDIUM | 5.5 | 0.2% | Jun 29, 2025 | A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flus... |
| CVE-2025-6854 | MEDIUM | 4.3 | 0.5% | Jun 29, 2025 | A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability... |
| CVE-2025-6849 | MEDIUM | 4.1 | 0.3% | Jun 29, 2025 | A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknow... |
| CVE-2025-6462 | MEDIUM | 5.4 | 0.2% | Jun 29, 2025 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-6839 | MEDIUM | 6.3 | 0.3% | Jun 29, 2025 | A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluat... |
| CVE-2025-53393 | MEDIUM | 6 | 0.2% | Jun 28, 2025 | In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. |
| CVE-2025-53392 | MEDIUM | 6.5 | 1.8% | Jun 28, 2025 | In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_comma... |
| CVE-2025-5937 | MEDIUM | 4.3 | 0.2% | Jun 28, 2025 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable ... |
| CVE-2025-38086 | MEDIUM | 5.5 | 0.2% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nw... |
| CVE-2025-38085 | MEDIUM | 4.7 | 0.1% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race... |
| CVE-2025-38084 | MEDIUM | 5.5 | 0.2% | Jun 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, n... |
| CVE-2025-6252 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ... |
| CVE-2025-6350 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-36027 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By pe... |
| CVE-2025-36026 | MEDIUM | 4.3 | 0.1% | Jun 28, 2025 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Atta... |
| CVE-2025-6778 | MEDIUM | 4.8 | 0.3% | Jun 27, 2025 | A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is ... |
| CVE-2025-6774 | MEDIUM | 6.3 | 0.3% | Jun 27, 2025 | A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is th... |
| CVE-2025-6773 | MEDIUM | 5.3 | 0.2% | Jun 27, 2025 | A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerabilit... |
| CVE-2025-6522 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerabl... |
| CVE-2025-46708 | MEDIUM | 4.3 | 0.2% | Jun 27, 2025 | Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from runn... |
| CVE-2025-46707 | MEDIUM | 5.2 | 0.1% | Jun 27, 2025 | Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU. |
| CVE-2025-44559 | MEDIUM | 6.5 | 0.2% | Jun 27, 2025 | An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth ra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now