2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36034 | MEDIUM | 5.9 | 0.1% | Jun 26, 2025 | IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in... |
| CVE-2025-6698 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been rated as problematic. Affected by this issue is so... |
| CVE-2025-6697 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2025-6696 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been classified as problematic. Affected is an unknown ... |
| CVE-2025-52902 | MEDIUM | 5.4 | 0.3% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52900 | MEDIUM | 5.5 | 0.2% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-6707 | MEDIUM | 5.4 | 0.1% | Jun 26, 2025 | Under certain conditions, an authenticated user request may execute with stale privileges following an intentional chang... |
| CVE-2025-6695 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown ... |
| CVE-2025-6694 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects ... |
| CVE-2025-6677 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs ... |
| CVE-2025-6676 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML ... |
| CVE-2025-6675 | MEDIUM | 4.8 | 0.2% | Jun 26, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
| CVE-2025-6674 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Y... |
| CVE-2025-5682 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki... |
| CVE-2025-52573 | MEDIUM | 6 | 0.7% | Jun 26, 2025 | iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulator... |
| CVE-2025-48923 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allo... |
| CVE-2025-48922 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox a... |
| CVE-2025-3773 | MEDIUM | 5.5 | 0.1% | Jun 26, 2025 | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authentic... |
| CVE-2025-3722 | MEDIUM | 4.4 | 0.2% | Jun 26, 2025 | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privi... |
| CVE-2025-6703 | MEDIUM | 6.5 | 0.2% | Jun 26, 2025 | Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0... |
| CVE-2025-6212 | MEDIUM | 6.1 | 0.3% | Jun 26, 2025 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m... |
| CVE-2025-5842 | MEDIUM | 5.4 | 0.3% | Jun 26, 2025 | The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in... |
| CVE-2025-5338 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all... |
| CVE-2025-5846 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1... |
| CVE-2025-5315 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now