2025 CVE Vulnerabilities
45,194 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4216 | MEDIUM | 6.4 | 0.2% | Jun 14, 2025 | The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' short... |
| CVE-2025-4187 | MEDIUM | 5.9 | 0.6% | Jun 14, 2025 | The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a... |
| CVE-2025-6059 | MEDIUM | 4.3 | 0.1% | Jun 14, 2025 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-6083 | MEDIUM | 4.3 | 0.2% | Jun 13, 2025 | In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id fi... |
| CVE-2025-49598 | MEDIUM | 4.4 | 0.1% | Jun 13, 2025 | conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feed... |
| CVE-2025-6035 | MEDIUM | 6.1 | 0.4% | Jun 13, 2025 | A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs du... |
| CVE-2025-48919 | MEDIUM | 5 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar... |
| CVE-2025-48917 | MEDIUM | 5 | 0.2% | Jun 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie C... |
| CVE-2025-48916 | MEDIUM | 6.5 | 0.2% | Jun 13, 2025 | Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Cal... |
| CVE-2025-28380 | MEDIUM | 6.1 | 0.3% | Jun 13, 2025 | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scri... |
| CVE-2025-46096 | MEDIUM | 6.1 | 0.5% | Jun 13, 2025 | Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-lu... |
| CVE-2025-36506 | MEDIUM | 6.9 | 0.4% | Jun 13, 2025 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an ... |
| CVE-2025-6012 | MEDIUM | 5.5 | 0.2% | Jun 13, 2025 | The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2025-5923 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in... |
| CVE-2025-22242 | MEDIUM | 5.6 | 0.1% | Jun 13, 2025 | Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method w... |
| CVE-2025-22241 | MEDIUM | 5.6 | 0.2% | Jun 13, 2025 | File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated inpu... |
| CVE-2025-22240 | MEDIUM | 6.3 | 0.1% | Jun 13, 2025 | Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.pa... |
| CVE-2025-22238 | MEDIUM | 4.2 | 0.3% | Jun 13, 2025 | Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traver... |
| CVE-2025-22237 | MEDIUM | 6.7 | 0.2% | Jun 13, 2025 | An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git ur... |
| CVE-2025-4229 | MEDIUM | 6 | 0.4% | Jun 13, 2025 | An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor... |
| CVE-2025-5815 | MEDIUM | 5.3 | 0.4% | Jun 13, 2025 | The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-5950 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versio... |
| CVE-2025-5939 | MEDIUM | 4.4 | 0.2% | Jun 13, 2025 | The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2025-5938 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request... |
| CVE-2025-5930 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now