2025 CVE Vulnerabilities
45,199 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5928 | MEDIUM | 4.3 | 0.1% | Jun 13, 2025 | The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up... |
| CVE-2025-5926 | MEDIUM | 6.1 | 0.1% | Jun 13, 2025 | The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0... |
| CVE-2025-5841 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all ver... |
| CVE-2025-5233 | MEDIUM | 6.4 | 0.2% | Jun 13, 2025 | The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versi... |
| CVE-2025-5123 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ p... |
| CVE-2025-4586 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' sh... |
| CVE-2025-4585 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode ... |
| CVE-2025-4584 | MEDIUM | 5.4 | 0.2% | Jun 13, 2025 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' short... |
| CVE-2025-4228 | MEDIUM | 4.6 | 0.2% | Jun 13, 2025 | An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated admi... |
| CVE-2025-4233 | MEDIUM | 5.1 | 0.2% | Jun 12, 2025 | An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypa... |
| CVE-2025-41234 | MEDIUM | 6.5 | 0.5% | Jun 12, 2025 | Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to ... |
| CVE-2025-41233 | MEDIUM | 6.8 | 0.3% | Jun 12, 2025 | Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated... |
| CVE-2025-49589 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE fu... |
| CVE-2025-44091 | MEDIUM | 5.4 | 0.2% | Jun 12, 2025 | yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function. |
| CVE-2025-4418 | MEDIUM | 6.7 | 0.1% | Jun 12, 2025 | An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 ... |
| CVE-2025-4417 | MEDIUM | 6.9 | 0.1% | Jun 12, 2025 | A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploi... |
| CVE-2025-2745 | MEDIUM | 6.5 | 0.2% | Jun 12, 2025 | A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could al... |
| CVE-2025-49579 | MEDIUM | 4.8 | 0.3% | Jun 12, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings ... |
| CVE-2025-49578 | MEDIUM | 5.4 | 0.4% | Jun 12, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `La... |
| CVE-2025-49577 | MEDIUM | 5.4 | 0.4% | Jun 12, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inse... |
| CVE-2025-49576 | MEDIUM | 5.4 | 0.4% | Jun 12, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title an... |
| CVE-2025-49575 | MEDIUM | 5.4 | 0.4% | Jun 12, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted... |
| CVE-2025-49081 | MEDIUM | 4.9 | 0.4% | Jun 12, 2025 | There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to se... |
| CVE-2025-36573 | MEDIUM | 5.5 | 0.1% | Jun 12, 2025 | Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul... |
| CVE-2025-29744 | MEDIUM | 5.4 | 0.2% | Jun 12, 2025 | pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now