2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52883 | MEDIUM | 5.3 | 0.2% | Jun 24, 2025 | Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacke... |
| CVE-2025-6557 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh... |
| CVE-2025-6556 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co... |
| CVE-2025-6555 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea... |
| CVE-2025-53021 | MEDIUM | 4.2 | 0.3% | Jun 24, 2025 | A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions ... |
| CVE-2025-52880 | MEDIUM | 4.2 | 0.3% | Jun 24, 2025 | Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be... |
| CVE-2025-5087 | MEDIUM | 6 | 0.2% | Jun 24, 2025 | Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capa... |
| CVE-2025-53073 | MEDIUM | 4.2 | 0.2% | Jun 24, 2025 | In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize... |
| CVE-2025-49147 | MEDIUM | 5.3 | 0.3% | Jun 24, 2025 | Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a... |
| CVE-2025-23260 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t... |
| CVE-2025-50699 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q... |
| CVE-2025-50695 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de... |
| CVE-2025-50693 | MEDIUM | 6.5 | 0.3% | Jun 24, 2025 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ... |
| CVE-2025-6569 | MEDIUM | 6.1 | 0.3% | Jun 24, 2025 | A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu... |
| CVE-2025-5318 | MEDIUM | 5.4 | 1.5% | Jun 24, 2025 | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_... |
| CVE-2025-6434 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking ... |
| CVE-2025-6431 | MEDIUM | 6.5 | 0.2% | Jun 24, 2025 | When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing... |
| CVE-2025-6430 | MEDIUM | 6.1 | 0.2% | Jun 24, 2025 | When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was ... |
| CVE-2025-6429 | MEDIUM | 6.5 | 0.3% | Jun 24, 2025 | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in... |
| CVE-2025-6428 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc... |
| CVE-2025-6425 | MEDIUM | 4.3 | 0.2% | Jun 24, 2025 | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified ... |
| CVE-2025-39201 | MEDIUM | 6.1 | 0.1% | Jun 24, 2025 | A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to... |
| CVE-2025-5258 | MEDIUM | 6.4 | 0.2% | Jun 24, 2025 | The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter... |
| CVE-2025-43877 | MEDIUM | 5.4 | 0.2% | Jun 24, 2025 | WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be... |
| CVE-2025-36519 | MEDIUM | 5.3 | 0.3% | Jun 24, 2025 | Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now