2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5286MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ pa...
CVE-2025-5122MEDIUM6.4The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all v...
CVE-2025-4687HIGH7.2In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the in...
CVE-2025-4670MEDIUM5.4The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored...
CVE-2025-27151CRITICAL9.8Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st...
CVE-2025-5276HIGH7.4Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the...
CVE-2025-5273MEDIUM6.9Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa...
CVE-2025-4583MEDIUM5.4The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-3755CRITICAL9.1Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation ME...
CVE-2025-27706LOW3.4CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to ver...
CVE-2025-27703MEDIUM6CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to ver...
CVE-2025-27702MEDIUM4.9CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers...
CVE-2025-5256MEDIUM5.4SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability...
CVE-2025-48749CRITICAL9.1Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Info...
CVE-2025-48747MEDIUM5Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor...
CVE-2025-47748MEDIUM5.3Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
CVE-2025-32803MEDIUM4In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, ...
CVE-2025-31501MEDIUM6.1Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
CVE-2025-31500MEDIUM6.1Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
CVE-2025-30087MEDIUM6.1Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete...
CVE-2025-1461MEDIUM5.6Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsa...
CVE-2025-5257MEDIUM6.5SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u...
CVE-2025-48931MEDIUM5.5The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibiliti...
CVE-2025-48930MEDIUM5.3The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content ma...
CVE-2025-48929CRITICAL9.8The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now