2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41437 | MEDIUM | 4.3 | 0.2% | Jun 9, 2025 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions... |
| CVE-2025-5872 | MEDIUM | 5.5 | 0.4% | Jun 9, 2025 | A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an ... |
| CVE-2025-5871 | MEDIUM | 5.5 | 0.4% | Jun 9, 2025 | A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue ... |
| CVE-2025-40675 | MEDIUM | 6.1 | 0.2% | Jun 9, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an atta... |
| CVE-2025-4652 | MEDIUM | 6.1 | 0.5% | Jun 9, 2025 | The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2025-47712 | MEDIUM | 6.5 | 0.4% | Jun 9, 2025 | A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client... |
| CVE-2025-47711 | MEDIUM | 6.5 | 0.4% | Jun 9, 2025 | There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a c... |
| CVE-2025-3582 | MEDIUM | 4.8 | 0.2% | Jun 9, 2025 | The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3581 | MEDIUM | 4.8 | 0.2% | Jun 9, 2025 | The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting ... |
| CVE-2025-25209 | MEDIUM | 5.7 | 0.2% | Jun 9, 2025 | The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those ... |
| CVE-2025-25208 | MEDIUM | 5.7 | 0.3% | Jun 9, 2025 | A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster |
| CVE-2025-25207 | MEDIUM | 5.7 | 0.3% | Jun 9, 2025 | The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authori... |
| CVE-2025-27563 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27247 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27242 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-27131 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-26693 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-26691 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-25217 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
| CVE-2025-24493 | MEDIUM | 4.7 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition. |
| CVE-2025-23235 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-21082 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-20063 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-38003 | MEDIUM | 5.5 | 0.2% | Jun 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procf... |
| CVE-2025-5836 | MEDIUM | 6.3 | 3.0% | Jun 7, 2025 | A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now