2025 CVE Vulnerabilities
45,187 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4775 | MEDIUM | 6.4 | 0.2% | Jun 17, 2025 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-48993 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27... |
| CVE-2025-48992 | MEDIUM | 4.8 | 0.2% | Jun 16, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27... |
| CVE-2025-6142 | MEDIUM | 6.3 | 0.2% | Jun 16, 2025 | A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerabil... |
| CVE-2025-6141 | MEDIUM | 4.8 | 0.2% | Jun 16, 2025 | A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affec... |
| CVE-2025-43200 | MEDIUM | 4.2 | 1.0% | Jun 16, 2025 | This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPad... |
| CVE-2025-27587 | MEDIUM | 5.3 | 0.4% | Jun 16, 2025 | OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the ... |
| CVE-2025-49134 | MEDIUM | 5.3 | 0.3% | Jun 16, 2025 | Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP addres... |
| CVE-2025-47951 | MEDIUM | 4.9 | 0.2% | Jun 16, 2025 | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject t... |
| CVE-2025-6131 | MEDIUM | 4.8 | 0.3% | Jun 16, 2025 | A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an un... |
| CVE-2025-2327 | MEDIUM | 5.1 | 0.2% | Jun 16, 2025 | A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured. |
| CVE-2025-6127 | MEDIUM | 5.4 | 0.2% | Jun 16, 2025 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Aff... |
| CVE-2025-6126 | MEDIUM | 5.4 | 0.3% | Jun 16, 2025 | A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected b... |
| CVE-2025-4565 | MEDIUM | 5.3 | 0.3% | Jun 16, 2025 | Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary numb... |
| CVE-2025-6125 | MEDIUM | 5.4 | 0.2% | Jun 16, 2025 | A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected... |
| CVE-2025-6120 | MEDIUM | 5.3 | 0.2% | Jun 16, 2025 | A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulne... |
| CVE-2025-46710 | MEDIUM | 5.7 | 0.2% | Jun 16, 2025 | Possible kernel exceptions caused by reading and writing kernel heap data after free. |
| CVE-2025-6119 | MEDIUM | 5.3 | 0.2% | Jun 16, 2025 | A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the f... |
| CVE-2025-4748 | MEDIUM | 4.8 | 0.2% | Jun 16, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modul... |
| CVE-2025-25265 | MEDIUM | 4.9 | 0.4% | Jun 16, 2025 | A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a... |
| CVE-2025-25264 | MEDIUM | 6.5 | 0.4% | Jun 16, 2025 | An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The curr... |
| CVE-2025-40729 | MEDIUM | 6.1 | 0.3% | Jun 16, 2025 | Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote... |
| CVE-2025-40727 | MEDIUM | 5.1 | 0.7% | Jun 16, 2025 | A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allo... |
| CVE-2025-40726 | MEDIUM | 5.1 | 0.7% | Jun 16, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers... |
| CVE-2025-2091 | MEDIUM | 5.4 | 0.2% | Jun 16, 2025 | An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows atta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now