2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49975 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss... |
| CVE-2025-49974 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allow... |
| CVE-2025-49973 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Siz... |
| CVE-2025-49972 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Reques... |
| CVE-2025-49971 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting ... |
| CVE-2025-49970 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Confi... |
| CVE-2025-49969 | MEDIUM | 4.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured A... |
| CVE-2025-49968 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cros... |
| CVE-2025-49967 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allo... |
| CVE-2025-49966 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API o... |
| CVE-2025-49965 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-c... |
| CVE-2025-49964 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issu... |
| CVE-2025-3228 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-3227 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-32876 | MEDIUM | 6.8 | 0.3% | Jun 20, 2025 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does no... |
| CVE-2025-32875 | MEDIUM | 5.7 | 0.1% | Jun 20, 2025 | An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither in... |
| CVE-2025-6341 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability ... |
| CVE-2025-6340 | MEDIUM | 5.4 | 0.2% | Jun 20, 2025 | A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects a... |
| CVE-2025-6336 | MEDIUM | 6.5 | 0.7% | Jun 20, 2025 | A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an... |
| CVE-2025-38083 | MEDIUM | 4.7 | 0.1% | Jun 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard... |
| CVE-2025-5963 | MEDIUM | 4.8 | 0.2% | Jun 20, 2025 | The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-envir... |
| CVE-2025-5255 | MEDIUM | 4.8 | 0.2% | Jun 20, 2025 | The Phoenix Code's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-... |
| CVE-2025-6257 | MEDIUM | 6.4 | 0.2% | Jun 20, 2025 | The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cur... |
| CVE-2025-50054 | MEDIUM | 5.5 | 0.2% | Jun 20, 2025 | Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user proc... |
| CVE-2025-5125 | MEDIUM | 4.8 | 0.2% | Jun 20, 2025 | The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the dat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now