2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5505 | MEDIUM | 4.8 | 0.4% | Jun 3, 2025 | A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects som... |
| CVE-2025-5504 | MEDIUM | 6.3 | 15.0% | Jun 3, 2025 | A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability af... |
| CVE-2025-46548 | MEDIUM | 6.5 | 0.7% | Jun 3, 2025 | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied... |
| CVE-2025-43925 | MEDIUM | 4.6 | 0.1% | Jun 3, 2025 | An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to... |
| CVE-2025-43924 | MEDIUM | 6.1 | 0.2% | Jun 3, 2025 | Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (f... |
| CVE-2025-43923 | MEDIUM | 6.5 | 0.2% | Jun 3, 2025 | An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Foca... |
| CVE-2025-5501 | MEDIUM | 6.9 | 0.6% | Jun 3, 2025 | A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi... |
| CVE-2025-45855 | MEDIUM | 5.4 | 0.3% | Jun 3, 2025 | An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers t... |
| CVE-2025-5340 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’... |
| CVE-2025-4671 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and com... |
| CVE-2025-4205 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all ver... |
| CVE-2025-5116 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ paramete... |
| CVE-2025-5103 | MEDIUM | 4.9 | 0.3% | Jun 3, 2025 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'defau... |
| CVE-2025-4420 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-1725 | MEDIUM | 6.4 | 0.2% | Jun 3, 2025 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner... |
| CVE-2025-41428 | MEDIUM | 6.9 | 0.6% | Jun 3, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. I... |
| CVE-2025-4567 | MEDIUM | 4.8 | 0.2% | Jun 3, 2025 | The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate ... |
| CVE-2025-3662 | MEDIUM | 6.1 | 0.2% | Jun 3, 2025 | The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to popul... |
| CVE-2025-3584 | MEDIUM | 4.8 | 0.2% | Jun 3, 2025 | The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which coul... |
| CVE-2025-31712 | MEDIUM | 6.2 | 0.1% | Jun 3, 2025 | In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial... |
| CVE-2025-31711 | MEDIUM | 6.2 | 0.1% | Jun 3, 2025 | In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of s... |
| CVE-2025-4047 | MEDIUM | 4.3 | 0.2% | Jun 3, 2025 | The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check... |
| CVE-2025-2939 | MEDIUM | 5.6 | 0.5% | Jun 3, 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up... |
| CVE-2025-49164 | MEDIUM | 4.3 | 0.1% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a48... |
| CVE-2025-49163 | MEDIUM | 6.7 | 0.1% | Jun 3, 2025 | Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now