2025 CVE Vulnerabilities
45,185 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38005 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent... |
| CVE-2025-23999 | MEDIUM | 4.3 | 0.2% | Jun 18, 2025 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-5981 | MEDIUM | 6.5 | 0.2% | Jun 18, 2025 | Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB... |
| CVE-2025-4955 | MEDIUM | 4.7 | 0.3% | Jun 18, 2025 | The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing the... |
| CVE-2025-49149 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by ... |
| CVE-2025-49593 | MEDIUM | 6.8 | 0.3% | Jun 17, 2025 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t... |
| CVE-2025-48443 | MEDIUM | 6.6 | 0.2% | Jun 17, 2025 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege E... |
| CVE-2025-30642 | MEDIUM | 5.5 | 0.1% | Jun 17, 2025 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial ... |
| CVE-2025-5141 | MEDIUM | 5.5 | 0.1% | Jun 17, 2025 | A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7... |
| CVE-2025-49487 | MEDIUM | 6.8 | 0.2% | Jun 17, 2025 | An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could h... |
| CVE-2025-45880 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows a... |
| CVE-2025-45878 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers t... |
| CVE-2025-45879 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers t... |
| CVE-2025-6196 | MEDIUM | 5.5 | 0.2% | Jun 17, 2025 | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when ope... |
| CVE-2025-49882 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer Cube... |
| CVE-2025-49881 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-49880 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ... |
| CVE-2025-49878 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPA... |
| CVE-2025-49877 | MEDIUM | 4.9 | 0.1% | Jun 17, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communit... |
| CVE-2025-49875 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Cont... |
| CVE-2025-49874 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in tychesoftwares Arconix FAQ arconix-faq allows Exploiting Incorrectly Configured A... |
| CVE-2025-49872 | MEDIUM | 5.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Accessing Functionality Not Properly Constrained ... |
| CVE-2025-49871 | MEDIUM | 5.9 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noptin Newsletter ... |
| CVE-2025-49868 | MEDIUM | 4.7 | 0.2% | Jun 17, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Aman FunnelKit Automations wp-marketing-automations... |
| CVE-2025-49865 | MEDIUM | 4.3 | 0.1% | Jun 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now