2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6071MEDIUM6.3Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to sal...
CVE-2025-53502MEDIUM6.5Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Sc...
CVE-2025-53500MEDIUM5.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53489MEDIUM5.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-49846MEDIUM4.1wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages t...
CVE-2025-48939MEDIUM4.2tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in...
CVE-2025-53490MEDIUM5.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-45938MEDIUM5.4Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName paramete...
CVE-2025-43713MEDIUM6.5ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows ...
CVE-2025-49618MEDIUM5.8In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, reg...
CVE-2025-49595MEDIUM4.9n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/bina...
CVE-2025-49032MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Guten...
CVE-2025-3702MEDIUM5.4Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting I...
CVE-2025-2537MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScrip...
CVE-2025-6563MEDIUM4.8A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attac...
CVE-2025-40723MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s...
CVE-2025-40722MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a s...
CVE-2025-2540MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto librar...
CVE-2025-27461MEDIUM6.8During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
CVE-2025-27460MEDIUM6.8The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an...
CVE-2025-27455MEDIUM6.1The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta...
CVE-2025-27454MEDIUM4.3The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitti...
CVE-2025-27453MEDIUM6.5The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such ...
CVE-2025-27451MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-27450MEDIUM6.5The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to esta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now