2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6716MEDIUM6.4The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str...
CVE-2025-5028MEDIUM6.8Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without...
CVE-2025-6200MEDIUM5.9The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before o...
CVE-2025-30024MEDIUM6.8The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the mid...
CVE-2025-2942MEDIUM4.3The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private po...
CVE-2025-53864MEDIUM5.8Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of...
CVE-2025-5241MEDIUM5.3Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows ...
CVE-2025-53519MEDIUM5.4A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-53471MEDIUM5.9Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has th...
CVE-2025-53397MEDIUM6.1A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-48496MEDIUM5.9Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that ...
CVE-2025-46704MEDIUM5.3A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory tr...
CVE-2025-41442MEDIUM5.4A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site...
CVE-2025-31267MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An a...
CVE-2025-6392MEDIUM4.4Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data...
CVE-2025-24798MEDIUM6.5Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that ...
CVE-2025-6390MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati...
CVE-2025-4662MEDIUM4.4Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut...
CVE-2025-2522MEDIUM6.5The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon...
CVE-2025-7021MEDIUM6.5Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on ...
CVE-2025-45662MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack...
CVE-2025-53709MEDIUM5.4Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The ...
CVE-2025-53626MEDIUM6.1pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 ...
CVE-2025-53549MEDIUM5.2The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection v...
CVE-2025-52473MEDIUM5.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now