2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24471 | MEDIUM | 6.5 | 0.3% | Jun 10, 2025 | An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below m... |
| CVE-2025-24069 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-24068 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-24065 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-22251 | MEDIUM | 5.3 | 0.3% | Jun 10, 2025 | An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 t... |
| CVE-2025-49143 | MEDIUM | 5.9 | 0.4% | Jun 10, 2025 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by ... |
| CVE-2025-48937 | MEDIUM | 4.9 | 0.3% | Jun 10, 2025 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 an... |
| CVE-2025-48879 | MEDIUM | 6.5 | 0.2% | Jun 10, 2025 | OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to sen... |
| CVE-2025-48067 | MEDIUM | 4.6 | 0.3% | Jun 10, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.... |
| CVE-2025-44043 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common... |
| CVE-2025-40569 | MEDIUM | 5.9 | 0.2% | Jun 10, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532... |
| CVE-2025-40568 | MEDIUM | 5.3 | 0.4% | Jun 10, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532... |
| CVE-2025-27207 | MEDIUM | 6.5 | 0.4% | Jun 10, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ... |
| CVE-2025-27206 | MEDIUM | 5.3 | 0.4% | Jun 10, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ... |
| CVE-2025-27505 | MEDIUM | 5.3 | 1.0% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the def... |
| CVE-2025-26395 | MEDIUM | 4.3 | 0.2% | Jun 10, 2025 | SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitiz... |
| CVE-2025-26394 | MEDIUM | 4.8 | 0.2% | Jun 10, 2025 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sani... |
| CVE-2025-49510 | MEDIUM | 4.3 | 0.1% | Jun 10, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce produc... |
| CVE-2025-49509 | MEDIUM | 5.3 | 0.3% | Jun 10, 2025 | Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting ... |
| CVE-2025-4774 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow... |
| CVE-2025-4577 | MEDIUM | 5.4 | 0.3% | Jun 10, 2025 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-43699 | MEDIUM | 5.3 | 0.4% | Jun 10, 2025 | Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of requ... |
| CVE-2025-2918 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mult... |
| CVE-2025-41657 | MEDIUM | 4.3 | 0.2% | Jun 10, 2025 | Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerpri... |
| CVE-2025-5742 | MEDIUM | 5.4 | 0.2% | Jun 10, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now