2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20304MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20303MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20289MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-60753MEDIUM5.5An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c whe...
CVE-2025-52602MEDIUM4.2HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint...
CVE-2025-11745MEDIUM6.4The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ...
CVE-2025-58337MEDIUM5.4An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, ...
CVE-2025-12469MEDIUM4.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12468MEDIUM5.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12192MEDIUM5.3The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15....
CVE-2025-11987MEDIUM6.4The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p...
CVE-2025-11820MEDIUM6.4The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl...
CVE-2025-12677MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12676MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5...
CVE-2025-12675MEDIUM4.3The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-12388MEDIUM6.4The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request F...
CVE-2025-11917MEDIUM6.4The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2025-11373MEDIUM4.3The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel...
CVE-2025-6027MEDIUM6.3The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associa...
CVE-2025-21078MEDIUM6.5Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a...
CVE-2025-21076MEDIUM5.5Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local ...
CVE-2025-21073MEDIUM4.1Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attacke...
CVE-2025-21071MEDIUM4.4Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged a...
CVE-2025-11072MEDIUM5.3The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloa...
CVE-2025-10873MEDIUM5.3The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-ma...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now