2025 CVE Vulnerabilities

45,180 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27028MEDIUM6.8The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file syst...
CVE-2025-27027MEDIUM4.1A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows onl...
CVE-2025-7378MEDIUM6An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR AD...
CVE-2025-7059MEDIUM6.4The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slideshow’ paramete...
CVE-2025-7213MEDIUM6.4A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function...
CVE-2025-5678MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2025-7209MEDIUM5.5A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerab...
CVE-2025-7207MEDIUM5.5A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope...
CVE-2025-3780MEDIUM6.5The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2025-47120MEDIUM5.5Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...
CVE-2025-47119MEDIUM5.5Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could...
CVE-2025-49547MEDIUM5.4Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-49534MEDIUM5.4Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-49525MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-49524MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-30313MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-27165MEDIUM5.5Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-7031MEDIUM5.3Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly C...
CVE-2025-7030MEDIUM6.5Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrec...
CVE-2025-49545MEDIUM6.2ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabil...
CVE-2025-49544MEDIUM6.8ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-49543MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...
CVE-2025-49542MEDIUM5.2ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerab...
CVE-2025-49541MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...
CVE-2025-49540MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now