2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46548MEDIUM6.5If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied...
CVE-2025-43925MEDIUM4.6An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to...
CVE-2025-43924MEDIUM6.1Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (f...
CVE-2025-43923MEDIUM6.5An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Foca...
CVE-2025-36564HIGH7.8Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal...
CVE-2025-5502CRITICAL9.8A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this...
CVE-2025-5501MEDIUM6.9A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi...
CVE-2025-5499CRITICAL9.8A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function ...
CVE-2025-5498HIGH7.2A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the...
CVE-2025-46154HIGH8.4Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
CVE-2025-45855MEDIUM5.4An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers t...
CVE-2025-5497CRITICAL9.8A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the...
CVE-2025-5495CRITICAL9.8A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow...
CVE-2025-4517CRITICAL9.4Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe...
CVE-2025-4435HIGH7.5When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members wo...
CVE-2025-4330HIGH7.5Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the...
CVE-2025-4138HIGH7.5Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the...
CVE-2025-5340MEDIUM6.4The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’...
CVE-2025-4671MEDIUM6.4The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and com...
CVE-2025-4205MEDIUM6.4The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all ver...
CVE-2025-5493CRITICAL9.8A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue ...
CVE-2025-5492HIGH8.8A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnera...
CVE-2025-4392HIGH7.2The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2025-31359HIGH8.8A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers...
CVE-2025-5116MEDIUM6.4The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ paramete...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now