2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20389MEDIUM6.5In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of th...
CVE-2025-20387MEDIUM6.5In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u...
CVE-2025-20386MEDIUM6.5In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to...
CVE-2025-20385MEDIUM4.8In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20384MEDIUM5.3In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20383MEDIUM4.3In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Sec...
CVE-2025-20382MEDIUM5.4In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20381MEDIUM5.4In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP)...
CVE-2025-13751MEDIUM5.5Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc...
CVE-2025-7044MEDIUM6.5An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged ...
CVE-2025-57202MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 Full...
CVE-2025-57200MEDIUM6.5AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-13949MEDIUM6.3A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /serv...
CVE-2025-13948MEDIUM5.6A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the ...
CVE-2025-13756MEDIUM4.3The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing ca...
CVE-2025-13401MEDIUM6.4The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox i...
CVE-2025-13359MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL...
CVE-2025-13354MEDIUM4.3The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization ...
CVE-2025-13109MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-12887MEDIUM5.4The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. Th...
CVE-2025-12358MEDIUM4.3The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2025-39665MEDIUM5.3User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate ...
CVE-2025-29864MEDIUM6.2Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZi...
CVE-2025-13472MEDIUM5.3A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of...
CVE-2025-13946MEDIUM5.5MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now