2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5964MEDIUM6.5A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to...
CVE-2025-6092MEDIUM4.3A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this ...
CVE-2025-5990MEDIUM5.4An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a ...
CVE-2025-6091HIGH8.8A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function Upd...
CVE-2025-6090HIGH8.8A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function Updat...
CVE-2025-22854MEDIUM6.9Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal u...
CVE-2025-21085LOW2.1PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory ut...
CVE-2025-6089MEDIUM6.1A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability a...
CVE-2025-36041CRITICAL9.8IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-1411HIGH7.8IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root d...
CVE-2025-5337MEDIUM5.4The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-5238MEDIUM6.4The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter i...
CVE-2025-4667MEDIUM6.4The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto...
CVE-2025-6070MEDIUM6.5The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,...
CVE-2025-6065CRITICAL9.1The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path...
CVE-2025-6064MEDIUM6.1The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-6063MEDIUM6.1The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-6062MEDIUM4.3The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-6061MEDIUM6.4The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod...
CVE-2025-6055MEDIUM6.1The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-6040MEDIUM6.1The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-5589MEDIUM6.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-cla...
CVE-2025-5336MEDIUM6.4The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter i...
CVE-2025-4592MEDIUM4.3The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2025-4216MEDIUM6.4The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' short...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now