2025 CVE Vulnerabilities
45,191 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6109 | MEDIUM | 4.3 | 0.4% | Jun 16, 2025 | A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic. Affected by this issue is ... |
| CVE-2025-6108 | MEDIUM | 6.3 | 0.4% | Jun 16, 2025 | A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has b... |
| CVE-2025-6106 | MEDIUM | 4.3 | 0.2% | Jun 16, 2025 | A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unkno... |
| CVE-2025-6101 | MEDIUM | 5.5 | 0.3% | Jun 16, 2025 | A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_m... |
| CVE-2025-6100 | MEDIUM | 6.3 | 0.2% | Jun 16, 2025 | A vulnerability was found in realguoshuai open-video-cms 1.0. It has been rated as critical. This issue affects some unk... |
| CVE-2025-6099 | MEDIUM | 5.5 | 0.4% | Jun 16, 2025 | A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared ... |
| CVE-2025-6093 | MEDIUM | 5.5 | 0.3% | Jun 15, 2025 | A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a27... |
| CVE-2025-5964 | MEDIUM | 6.5 | 10.3% | Jun 15, 2025 | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to... |
| CVE-2025-6092 | MEDIUM | 4.3 | 0.3% | Jun 15, 2025 | A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this ... |
| CVE-2025-5990 | MEDIUM | 5.4 | 0.2% | Jun 15, 2025 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a ... |
| CVE-2025-22854 | MEDIUM | 6.9 | 0.3% | Jun 15, 2025 | Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal u... |
| CVE-2025-6089 | MEDIUM | 6.1 | 0.3% | Jun 15, 2025 | A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability a... |
| CVE-2025-5337 | MEDIUM | 5.4 | 0.2% | Jun 14, 2025 | The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-5238 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter i... |
| CVE-2025-4667 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto... |
| CVE-2025-6070 | MEDIUM | 6.5 | 0.6% | Jun 14, 2025 | The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,... |
| CVE-2025-6064 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-6063 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-6062 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-6061 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod... |
| CVE-2025-6055 | MEDIUM | 6.1 | 0.1% | Jun 14, 2025 | The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-6040 | MEDIUM | 6.1 | 0.2% | Jun 14, 2025 | The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-5589 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-cla... |
| CVE-2025-5336 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter i... |
| CVE-2025-4592 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now