2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40775HIGH7.5When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta...
CVE-2025-1421LOW2.4Data provided in a request performed to the server while activating a new device are put in a database. Other high privi...
CVE-2025-1420LOW2.4Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-p...
CVE-2025-1419LOW2.4Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perfo...
CVE-2025-1418MEDIUM5.1A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which cont...
CVE-2025-1417MEDIUM4.6In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by...
CVE-2025-1416HIGH7In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities res...
CVE-2025-4803HIGH7.2The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection ...
CVE-2025-4611MEDIUM6.4The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2025-4221MEDIUM6.4The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader...
CVE-2025-4219MEDIUM6.4The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all v...
CVE-2025-4217MEDIUM6.4The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_yo...
CVE-2025-4105MEDIUM5.4The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on ...
CVE-2025-48414MEDIUM6.5There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts ...
CVE-2025-48413HIGH7.7The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr...
CVE-2025-41232CRITICAL9.1Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an autho...
CVE-2025-3781MEDIUM6.4The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_don...
CVE-2025-3750MEDIUM6.4The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ param...
CVE-2025-27804MEDIUM6.5Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishi...
CVE-2025-27803MEDIUM6.5The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network ac...
CVE-2025-1415MEDIUM5.1A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Dev...
CVE-2025-1712HIGH8.8Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat...
CVE-2025-4949MEDIUM5.3In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the Amazo...
CVE-2025-4524CRITICAL9.8The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclu...
CVE-2025-5013MEDIUM4.7A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown par...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now