2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43886MEDIUM4.4Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerabili...
CVE-2025-43884MEDIUM6.7Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele...
CVE-2025-29592MEDIUM5.6oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
CVE-2025-20248MEDIUM6A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp...
CVE-2025-20159MEDIUM5.3A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could ...
CVE-2025-56578MEDIUM5.7An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the...
CVE-2025-10227MEDIUM4.6Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2...
CVE-2025-10222MEDIUM4.8Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon...
CVE-2025-10221MEDIUM6.7Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet ...
CVE-2025-40725MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute J...
CVE-2025-36758MEDIUM6.3It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Pas...
CVE-2025-36757MEDIUM6.3It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp...
CVE-2025-36756MEDIUM5.8A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t...
CVE-2025-9979MEDIUM4.3The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin...
CVE-2025-9888MEDIUM4.3The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-9857MEDIUM6.4The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-9622MEDIUM4.3The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-9463MEDIUM6.5The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v...
CVE-2025-9367MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up...
CVE-2025-8778MEDIUM4.3The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-7843MEDIUM6.4The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-7826MEDIUM6.5The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ...
CVE-2025-6189MEDIUM6.5The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ...
CVE-2025-10142MEDIUM4.9The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa...
CVE-2025-10126MEDIUM6.4The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now