2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3766MEDIUM5.4The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil...
CVE-2025-4220MEDIUM6.4The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' ...
CVE-2025-4055MEDIUM6.4The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s...
CVE-2025-4054MEDIUM6.1The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights fu...
CVE-2025-3924MEDIUM5.3The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public...
CVE-2025-3860MEDIUM6.4The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in al...
CVE-2025-3853MEDIUM6.5The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2....
CVE-2025-3851MEDIUM4.3The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire...
CVE-2025-2821MEDIUM5.3The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-3218MEDIUM5.4IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation ...
CVE-2025-47418MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi...
CVE-2025-47417MEDIUM5.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi...
CVE-2025-47256MEDIUM5.6Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha form...
CVE-2025-4388MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-44900MEDIUM6.5In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the m...
CVE-2025-37730MEDIUM6.5Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod...
CVE-2025-46736MEDIUM5.3Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal...
CVE-2025-45250MEDIUM5.5MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/u...
CVE-2025-32022MEDIUM4.6Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot whi...
CVE-2025-26262MEDIUM6.5An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate...
CVE-2025-4384MEDIUM6The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet becom...
CVE-2025-23379MEDIUM5.2Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During We...
CVE-2025-22479MEDIUM4.3Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Res...
CVE-2025-4374MEDIUM6.5A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't bee...
CVE-2025-4373MEDIUM4.8A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now