2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3473 | MEDIUM | 6.7 | 0.1% | Jun 11, 2025 | IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inhe... |
| CVE-2025-0163 | MEDIUM | 5.3 | 0.3% | Jun 11, 2025 | IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames... |
| CVE-2025-4605 | MEDIUM | 6.6 | 0.2% | Jun 11, 2025 | A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnera... |
| CVE-2025-35941 | MEDIUM | 5.5 | 0.3% | Jun 11, 2025 | A password is exposed locally. |
| CVE-2025-5144 | MEDIUM | 5.4 | 0.2% | Jun 11, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ paramete... |
| CVE-2025-5986 | MEDIUM | 6.5 | 0.5% | Jun 11, 2025 | A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's de... |
| CVE-2025-4573 | MEDIUM | 4.1 | 0.2% | Jun 11, 2025 | Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LD... |
| CVE-2025-4128 | MEDIUM | 4.3 | 0.2% | Jun 11, 2025 | Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi... |
| CVE-2025-26412 | MEDIUM | 6.8 | 0.3% | Jun 11, 2025 | The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with ... |
| CVE-2025-4798 | MEDIUM | 4.9 | 0.4% | Jun 11, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1... |
| CVE-2025-4666 | MEDIUM | 6.4 | 0.3% | Jun 11, 2025 | The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versi... |
| CVE-2025-30675 | MEDIUM | 4.7 | 0.6% | Jun 11, 2025 | In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or ... |
| CVE-2025-1055 | MEDIUM | 5.6 | 0.2% | Jun 11, 2025 | A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use... |
| CVE-2025-5984 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe... |
| CVE-2025-47117 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47116 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47115 | MEDIUM | 5.4 | 0.3% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47114 | MEDIUM | 5.4 | 0.3% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47113 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47094 | MEDIUM | 6.1 | 0.3% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-47093 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47092 | MEDIUM | 5.4 | 0.3% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47091 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47090 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-47089 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now