2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2537 | MEDIUM | 6.4 | 0.2% | Jul 3, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScrip... |
| CVE-2025-6563 | MEDIUM | 4.8 | 0.6% | Jul 3, 2025 | A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attac... |
| CVE-2025-40723 | MEDIUM | 5.1 | 0.3% | Jul 3, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s... |
| CVE-2025-40722 | MEDIUM | 5.1 | 0.3% | Jul 3, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s... |
| CVE-2025-2540 | MEDIUM | 6.4 | 0.3% | Jul 3, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto librar... |
| CVE-2025-27461 | MEDIUM | 6.8 | 0.2% | Jul 3, 2025 | During startup, the device automatically logs in the EPC2 Windows user without requesting a password. |
| CVE-2025-27460 | MEDIUM | 6.8 | 0.1% | Jul 3, 2025 | The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an... |
| CVE-2025-27459 | HIGH | 7.5 | 0.2% | Jul 3, 2025 | The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th... |
| CVE-2025-27458 | HIGH | 7.5 | 0.2% | Jul 3, 2025 | The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password... |
| CVE-2025-27457 | HIGH | 7.5 | 0.2% | Jul 3, 2025 | All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic ... |
| CVE-2025-27456 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp... |
| CVE-2025-27455 | MEDIUM | 6.1 | 0.3% | Jul 3, 2025 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta... |
| CVE-2025-27454 | MEDIUM | 4.3 | 0.2% | Jul 3, 2025 | The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitti... |
| CVE-2025-27453 | MEDIUM | 6.5 | 0.4% | Jul 3, 2025 | The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such ... |
| CVE-2025-27452 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. The... |
| CVE-2025-27451 | MEDIUM | 5.3 | 0.3% | Jul 3, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to... |
| CVE-2025-27450 | MEDIUM | 6.5 | 0.2% | Jul 3, 2025 | The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to esta... |
| CVE-2025-27449 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh... |
| CVE-2025-27448 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject... |
| CVE-2025-27447 | MEDIUM | 6.1 | 0.3% | Jul 3, 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects... |
| CVE-2025-1711 | HIGH | 7.5 | 0.3% | Jul 3, 2025 | Multiple services of the DUT as well as different scopes of the same service reuse the same credentials. |
| CVE-2025-1710 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi... |
| CVE-2025-1709 | MEDIUM | 6.5 | 0.3% | Jul 3, 2025 | Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded). |
| CVE-2025-1708 | HIGH | 7.5 | 0.4% | Jul 3, 2025 | The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its... |
| CVE-2025-6587 | MEDIUM | 5.2 | 0.1% | Jul 3, 2025 | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This lead... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now