2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4229MEDIUM6An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor...
CVE-2025-4227LOW3.5An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g...
CVE-2025-5815MEDIUM5.3The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-5282HIGH7.5The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l...
CVE-2025-5950MEDIUM5.4The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versio...
CVE-2025-5939MEDIUM4.4The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2025-5938MEDIUM4.3The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request...
CVE-2025-5930MEDIUM4.3The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2...
CVE-2025-5928MEDIUM4.3The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
CVE-2025-5926MEDIUM6.1The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0...
CVE-2025-5841MEDIUM6.4The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all ver...
CVE-2025-5491HIGH8.8Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a cu...
CVE-2025-5288CRITICAL9.8The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri...
CVE-2025-5233MEDIUM6.4The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versi...
CVE-2025-5123MEDIUM5.4The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ p...
CVE-2025-4586MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' sh...
CVE-2025-4585MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode ...
CVE-2025-4584MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' short...
CVE-2025-47959HIGH7.1Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize...
CVE-2025-30399HIGH7.5Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2025-4232HIGH8.8An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™...
CVE-2025-4231HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform ...
CVE-2025-4230HIGH8.4A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2025-4228MEDIUM4.6An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated admi...
CVE-2025-4233MEDIUM5.1An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now