2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22244 | MEDIUM | 6.9 | 0.3% | Jun 4, 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input vali... |
| CVE-2025-2336 | MEDIUM | 4.8 | 0.4% | Jun 4, 2025 | Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'n... |
| CVE-2025-20279 | MEDIUM | 4.8 | 0.2% | Jun 4, 2025 | A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker... |
| CVE-2025-20278 | MEDIUM | 6.7 | 0.2% | Jun 4, 2025 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacke... |
| CVE-2025-20277 | MEDIUM | 6.7 | 0.1% | Jun 4, 2025 | A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker ... |
| CVE-2025-20273 | MEDIUM | 6.1 | 0.2% | Jun 4, 2025 | A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could a... |
| CVE-2025-20259 | MEDIUM | 5.3 | 0.1% | Jun 4, 2025 | Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authentic... |
| CVE-2025-20129 | MEDIUM | 5.4 | 0.3% | Jun 4, 2025 | A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMin... |
| CVE-2025-29094 | MEDIUM | 6.1 | 0.3% | Jun 4, 2025 | Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbi... |
| CVE-2025-23106 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo... |
| CVE-2025-23101 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privi... |
| CVE-2025-23096 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro... |
| CVE-2025-23095 | MEDIUM | 6.5 | 0.2% | Jun 4, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro... |
| CVE-2025-48962 | MEDIUM | 4.3 | 0.2% | Jun 4, 2025 | Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Li... |
| CVE-2025-48960 | MEDIUM | 5.9 | 0.1% | Jun 4, 2025 | Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Wi... |
| CVE-2025-48959 | MEDIUM | 6.7 | 0.1% | Jun 4, 2025 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect ... |
| CVE-2025-5601 | MEDIUM | 6.5 | 0.3% | Jun 4, 2025 | Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or... |
| CVE-2025-5584 | MEDIUM | 5.4 | 0.3% | Jun 4, 2025 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected ... |
| CVE-2025-27444 | MEDIUM | 4.8 | 0.3% | Jun 4, 2025 | A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from th... |
| CVE-2025-4580 | MEDIUM | 4.3 | 0.1% | Jun 4, 2025 | The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2025-48710 | MEDIUM | 4.1 | 0.3% | Jun 4, 2025 | kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefin... |
| CVE-2025-5539 | MEDIUM | 6.4 | 0.2% | Jun 4, 2025 | The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-20996 | MEDIUM | 5 | 0.1% | Jun 4, 2025 | Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers... |
| CVE-2025-20993 | MEDIUM | 6.8 | 0.1% | Jun 4, 2025 | Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write o... |
| CVE-2025-20991 | MEDIUM | 5.1 | 0.1% | Jun 4, 2025 | Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now