2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49162 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a ... |
| CVE-2025-3919 | MEDIUM | 6.4 | 0.2% | Jun 2, 2025 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2025-48996 | MEDIUM | 5.3 | 0.3% | Jun 2, 2025 | HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthentic... |
| CVE-2025-47585 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme... |
| CVE-2025-49069 | MEDIUM | 4.3 | 0.1% | Jun 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Requ... |
| CVE-2025-45387 | MEDIUM | 5.4 | 0.2% | Jun 2, 2025 | osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php. |
| CVE-2025-27955 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and... |
| CVE-2025-27954 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut... |
| CVE-2025-27953 | MEDIUM | 6.5 | 0.3% | Jun 2, 2025 | An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut... |
| CVE-2025-23104 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privi... |
| CVE-2025-20297 | MEDIUM | 5.4 | 13.1% | Jun 2, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2... |
| CVE-2025-48995 | MEDIUM | 6.9 | 0.2% | Jun 2, 2025 | SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat... |
| CVE-2025-48994 | MEDIUM | 6.9 | 0.2% | Jun 2, 2025 | SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat... |
| CVE-2025-48941 | MEDIUM | 5.3 | 0.3% | Jun 2, 2025 | MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions... |
| CVE-2025-44115 | MEDIUM | 5.4 | 0.2% | Jun 2, 2025 | A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&... |
| CVE-2025-44172 | MEDIUM | 6.5 | 0.2% | Jun 2, 2025 | Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement ... |
| CVE-2025-20001 | MEDIUM | 6.5 | 0.5% | Jun 2, 2025 | An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trig... |
| CVE-2025-46806 | MEDIUM | 6.9 | 0.4% | Jun 2, 2025 | A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue a... |
| CVE-2025-48958 | MEDIUM | 5.4 | 0.3% | Jun 2, 2025 | Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the cu... |
| CVE-2025-48955 | MEDIUM | 6.2 | 0.1% | Jun 2, 2025 | Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers... |
| CVE-2025-48495 | MEDIUM | 5.4 | 0.1% | Jun 2, 2025 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly n... |
| CVE-2025-48494 | MEDIUM | 5.4 | 0.1% | Jun 2, 2025 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encr... |
| CVE-2025-47272 | MEDIUM | 5.5 | 0.1% | Jun 2, 2025 | The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to ... |
| CVE-2025-3454 | MEDIUM | 5 | 0.4% | Jun 2, 2025 | This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash... |
| CVE-2025-5437 | MEDIUM | 6.9 | 0.4% | Jun 2, 2025 | A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now