2025 CVE Vulnerabilities
45,199 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49193 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The application fails to implement several security headers. These headers help increase the overall security level of t... |
| CVE-2025-49192 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta... |
| CVE-2025-49191 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded... |
| CVE-2025-49190 | MEDIUM | 5.8 | 0.3% | Jun 12, 2025 | The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal req... |
| CVE-2025-49189 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via cl... |
| CVE-2025-49187 | MEDIUM | 5.3 | 0.3% | Jun 12, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to... |
| CVE-2025-49186 | MEDIUM | 6.5 | 0.3% | Jun 12, 2025 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short tim... |
| CVE-2025-49185 | MEDIUM | 5.4 | 0.2% | Jun 12, 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can... |
| CVE-2025-5195 | MEDIUM | 4.3 | 0.2% | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2025-5996 | MEDIUM | 6.5 | 0.6% | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and... |
| CVE-2025-2254 | MEDIUM | 6.1 | 0.3% | Jun 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and ... |
| CVE-2025-6003 | MEDIUM | 5.3 | 0.3% | Jun 12, 2025 | The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capa... |
| CVE-2025-5301 | MEDIUM | 6.1 | 34.9% | Jun 12, 2025 | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS... |
| CVE-2025-40592 | MEDIUM | 6.1 | 0.4% | Jun 12, 2025 | A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All vers... |
| CVE-2025-32466 | MEDIUM | 6.7 | 0.3% | Jun 11, 2025 | A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs wit... |
| CVE-2025-49150 | MEDIUM | 5.9 | 0.3% | Jun 11, 2025 | Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enab... |
| CVE-2025-0923 | MEDIUM | 5.3 | 0.2% | Jun 11, 2025 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source co... |
| CVE-2025-0917 | MEDIUM | 4.8 | 0.2% | Jun 11, 2025 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to... |
| CVE-2025-0913 | MEDIUM | 5.5 | 0.2% | Jun 11, 2025 | os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a danglin... |
| CVE-2025-4673 | MEDIUM | 6.8 | 0.6% | Jun 11, 2025 | Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive inf... |
| CVE-2025-26383 | MEDIUM | 6.3 | 0.2% | Jun 11, 2025 | The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized d... |
| CVE-2025-49146 | MEDIUM | 5.9 | 0.5% | Jun 11, 2025 | pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is config... |
| CVE-2025-48448 | MEDIUM | 6.5 | 0.3% | Jun 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocati... |
| CVE-2025-48444 | MEDIUM | 5.3 | 0.2% | Jun 11, 2025 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl... |
| CVE-2025-48013 | MEDIUM | 5.3 | 0.2% | Jun 11, 2025 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now