2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6068MEDIUM5.4The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2025-5530MEDIUM5.4The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-4593MEDIUM6.5The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2025-6716MEDIUM6.4The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str...
CVE-2025-5028MEDIUM6.8Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without...
CVE-2025-6200MEDIUM5.9The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before o...
CVE-2025-30024MEDIUM6.8The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the mid...
CVE-2025-2942MEDIUM4.3The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private po...
CVE-2025-53864MEDIUM5.8Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of...
CVE-2025-5241MEDIUM5.3Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows ...
CVE-2025-53519MEDIUM5.4A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-53471MEDIUM5.9Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has th...
CVE-2025-53397MEDIUM6.1A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-48496MEDIUM5.9Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that ...
CVE-2025-46704MEDIUM5.3A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory tr...
CVE-2025-41442MEDIUM5.4A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-31267MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An a...
CVE-2025-6392MEDIUM4.4Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data...
CVE-2025-24798MEDIUM6.5Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that ...
CVE-2025-6390MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati...
CVE-2025-4662MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut...
CVE-2025-2522MEDIUM6.5The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon...
CVE-2025-7021MEDIUM6.5Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on ...
CVE-2025-45662MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack...
CVE-2025-53709MEDIUM5.4Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now