2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2537MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScrip...
CVE-2025-6563MEDIUM4.8A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attac...
CVE-2025-40723MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s...
CVE-2025-40722MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s...
CVE-2025-2540MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto librar...
CVE-2025-27461MEDIUM6.8During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
CVE-2025-27460MEDIUM6.8The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an...
CVE-2025-27459HIGH7.5The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th...
CVE-2025-27458HIGH7.5The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password...
CVE-2025-27457HIGH7.5All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic ...
CVE-2025-27456CRITICAL9.8The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp...
CVE-2025-27455MEDIUM6.1The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta...
CVE-2025-27454MEDIUM4.3The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitti...
CVE-2025-27453MEDIUM6.5The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such ...
CVE-2025-27452HIGH7.5The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. The...
CVE-2025-27451MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-27450MEDIUM6.5The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to esta...
CVE-2025-27449CRITICAL9.8The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh...
CVE-2025-27448MEDIUM5.4The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject...
CVE-2025-27447MEDIUM6.1The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects...
CVE-2025-1711HIGH7.5Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
CVE-2025-1710CRITICAL9.8The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi...
CVE-2025-1709MEDIUM6.5Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
CVE-2025-1708HIGH7.5The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its...
CVE-2025-6587MEDIUM5.2System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This lead...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now