2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6068 | MEDIUM | 5.4 | 0.2% | Jul 11, 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl... |
| CVE-2025-5530 | MEDIUM | 5.4 | 0.2% | Jul 11, 2025 | The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-4593 | MEDIUM | 6.5 | 0.3% | Jul 11, 2025 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2025-6716 | MEDIUM | 6.4 | 0.2% | Jul 11, 2025 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str... |
| CVE-2025-5028 | MEDIUM | 6.8 | 0.1% | Jul 11, 2025 | Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without... |
| CVE-2025-6200 | MEDIUM | 5.9 | 0.2% | Jul 11, 2025 | The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before o... |
| CVE-2025-30024 | MEDIUM | 6.8 | 0.3% | Jul 11, 2025 | The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the mid... |
| CVE-2025-2942 | MEDIUM | 4.3 | 0.3% | Jul 11, 2025 | The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private po... |
| CVE-2025-53864 | MEDIUM | 5.8 | 0.8% | Jul 11, 2025 | Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of... |
| CVE-2025-5241 | MEDIUM | 5.3 | 0.4% | Jul 11, 2025 | Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows ... |
| CVE-2025-53519 | MEDIUM | 5.4 | 0.2% | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site... |
| CVE-2025-53471 | MEDIUM | 5.9 | 0.2% | Jul 11, 2025 | Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has th... |
| CVE-2025-53397 | MEDIUM | 6.1 | 0.2% | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site... |
| CVE-2025-48496 | MEDIUM | 5.9 | 0.2% | Jul 11, 2025 | Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that ... |
| CVE-2025-46704 | MEDIUM | 5.3 | 3.3% | Jul 11, 2025 | A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory tr... |
| CVE-2025-41442 | MEDIUM | 5.4 | 0.2% | Jul 11, 2025 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site... |
| CVE-2025-31267 | MEDIUM | 4.6 | 0.2% | Jul 10, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An a... |
| CVE-2025-6392 | MEDIUM | 4.4 | 0.1% | Jul 10, 2025 | Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data... |
| CVE-2025-24798 | MEDIUM | 6.5 | 0.4% | Jul 10, 2025 | Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that ... |
| CVE-2025-6390 | MEDIUM | 4.4 | 0.1% | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati... |
| CVE-2025-4662 | MEDIUM | 4.4 | 0.1% | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut... |
| CVE-2025-2522 | MEDIUM | 6.5 | 0.2% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon... |
| CVE-2025-7021 | MEDIUM | 6.5 | 0.3% | Jul 10, 2025 | Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on ... |
| CVE-2025-45662 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack... |
| CVE-2025-53709 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now