2025 CVE Vulnerabilities

45,194 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4216MEDIUM6.4The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' short...
CVE-2025-4187MEDIUM5.9The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a...
CVE-2025-6059MEDIUM4.3The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-6083MEDIUM4.3In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id fi...
CVE-2025-49598MEDIUM4.4conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feed...
CVE-2025-6035MEDIUM6.1A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs du...
CVE-2025-48919MEDIUM5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar...
CVE-2025-48917MEDIUM5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie C...
CVE-2025-48916MEDIUM6.5Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Cal...
CVE-2025-28380MEDIUM6.1A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scri...
CVE-2025-46096MEDIUM6.1Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-lu...
CVE-2025-36506MEDIUM6.9External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an ...
CVE-2025-6012MEDIUM5.5The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2025-5923MEDIUM6.4The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in...
CVE-2025-22242MEDIUM5.6Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method w...
CVE-2025-22241MEDIUM5.6File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated inpu...
CVE-2025-22240MEDIUM6.3Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.pa...
CVE-2025-22238MEDIUM4.2Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traver...
CVE-2025-22237MEDIUM6.7An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git ur...
CVE-2025-4229MEDIUM6An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor...
CVE-2025-5815MEDIUM5.3The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-5950MEDIUM5.4The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versio...
CVE-2025-5939MEDIUM4.4The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2025-5938MEDIUM4.3The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request...
CVE-2025-5930MEDIUM4.3The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now