2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10268 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path travers... |
| CVE-2025-60465 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02... |
| CVE-2025-60473 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-60466 | MEDIUM | 5 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0... |
| CVE-2025-60468 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflo... |
| CVE-2025-64719 | MEDIUM | 4.9 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a ... |
| CVE-2025-60471 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4B... |
| CVE-2025-64105 | MEDIUM | 5.1 | 0.3% | Jun 23, 2026 | FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s... |
| CVE-2025-13162 | MEDIUM | 4.4 | 0.1% | Jun 23, 2026 | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect... |
| CVE-2025-55639 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed... |
| CVE-2025-33128 | MEDIUM | 5.4 | 0.1% | Jun 22, 2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab... |
| CVE-2025-2669 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri... |
| CVE-2025-62198 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend... |
| CVE-2025-71331 | MEDIUM | 6.1 | 0.2% | Jun 20, 2026 | Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ... |
| CVE-2025-15661 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()... |
| CVE-2025-32748 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate... |
| CVE-2025-15657 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. |
| CVE-2025-69137 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Subscriber Broken Access Control in Genemy <= 1.6.6 versions. |
| CVE-2025-62340 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where ... |
| CVE-2025-48571 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er... |
| CVE-2025-15642 | MEDIUM | 6.8 | 0.1% | Jun 17, 2026 | Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad... |
| CVE-2025-15641 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad... |
| CVE-2025-9912 | MEDIUM | 6.3 | 0.1% | Jun 16, 2026 | Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit... |
| CVE-2025-10262 | MEDIUM | 6.3 | 0.1% | Jun 16, 2026 | Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu... |
| CVE-2025-69332 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | Subscriber Broken Access Control in Bookify <= 1.1.1 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now