2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30084 | MEDIUM | 6.1 | 0.2% | Jun 5, 2025 | A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the... |
| CVE-2025-27754 | MEDIUM | 6.5 | 0.2% | Jun 5, 2025 | A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows auth... |
| CVE-2025-27753 | MEDIUM | 6.5 | 0.2% | Jun 5, 2025 | A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to th... |
| CVE-2025-27445 | MEDIUM | 5.4 | 0.4% | Jun 5, 2025 | A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allow... |
| CVE-2025-0691 | MEDIUM | 5 | 0.3% | Jun 5, 2025 | Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated u... |
| CVE-2025-5341 | MEDIUM | 6.4 | 0.2% | Jun 5, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-5651 | MEDIUM | 5.4 | 0.2% | Jun 5, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1... |
| CVE-2025-5649 | MEDIUM | 6.5 | 0.5% | Jun 5, 2025 | A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affec... |
| CVE-2025-5683 | MEDIUM | 5.5 | 0.2% | Jun 5, 2025 | When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects ... |
| CVE-2025-5640 | MEDIUM | 4.8 | 0.9% | Jun 5, 2025 | A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function Mavl... |
| CVE-2025-49466 | MEDIUM | 5.8 | 0.6% | Jun 5, 2025 | aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the n... |
| CVE-2025-48432 | MEDIUM | 5.3 | 0.6% | Jun 5, 2025 | An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response log... |
| CVE-2025-5628 | MEDIUM | 5.4 | 0.3% | Jun 5, 2025 | A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected b... |
| CVE-2025-49007 | MEDIUM | 5.3 | 0.5% | Jun 4, 2025 | Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of... |
| CVE-2025-5690 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules define... |
| CVE-2025-48934 | MEDIUM | 5.3 | 0.4% | Jun 4, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` ... |
| CVE-2025-48888 | MEDIUM | 5.3 | 0.3% | Jun 4, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.... |
| CVE-2025-46339 | MEDIUM | 4.3 | 0.2% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding ... |
| CVE-2025-46204 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint. |
| CVE-2025-46203 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint. |
| CVE-2025-46011 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers... |
| CVE-2025-32015 | MEDIUM | 6.7 | 0.4% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe... |
| CVE-2025-31482 | MEDIUM | 4.3 | 0.2% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedl... |
| CVE-2025-31136 | MEDIUM | 5.4 | 0.3% | Jun 4, 2025 | FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the... |
| CVE-2025-22245 | MEDIUM | 5.9 | 0.2% | Jun 4, 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validatio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now