2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5505MEDIUM4.8A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects som...
CVE-2025-5504MEDIUM6.3A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability af...
CVE-2025-46548MEDIUM6.5If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied...
CVE-2025-43925MEDIUM4.6An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to...
CVE-2025-43924MEDIUM6.1Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (f...
CVE-2025-43923MEDIUM6.5An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Foca...
CVE-2025-5501MEDIUM6.9A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi...
CVE-2025-45855MEDIUM5.4An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers t...
CVE-2025-5340MEDIUM6.4The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’...
CVE-2025-4671MEDIUM6.4The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and com...
CVE-2025-4205MEDIUM6.4The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all ver...
CVE-2025-5116MEDIUM6.4The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ paramete...
CVE-2025-5103MEDIUM4.9The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'defau...
CVE-2025-4420MEDIUM6.4The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-1725MEDIUM6.4The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner...
CVE-2025-41428MEDIUM6.9Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. I...
CVE-2025-4567MEDIUM4.8The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate ...
CVE-2025-3662MEDIUM6.1The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to popul...
CVE-2025-3584MEDIUM4.8The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which coul...
CVE-2025-31712MEDIUM6.2In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial...
CVE-2025-31711MEDIUM6.2In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of s...
CVE-2025-4047MEDIUM4.3The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check...
CVE-2025-2939MEDIUM5.6The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
CVE-2025-49164MEDIUM4.3Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a48...
CVE-2025-49163MEDIUM6.7Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now