2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41724HIGH7.5An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process wi...
CVE-2025-41723CRITICAL9.8The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ...
CVE-2025-41722HIGH7.5The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attac...
CVE-2025-41721LOW2.7A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat...
CVE-2025-41720MEDIUM4.3A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv...
CVE-2025-41719HIGH8.8A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsuppor...
CVE-2025-12033MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2025-10588MEDIUM4.3The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2025-10570MEDIUM4.3The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all ...
CVE-2025-5983MEDIUM6.5The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.
CVE-2025-10651MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in...
CVE-2025-10638MEDIUM5.3The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allo...
CVE-2025-62775HIGH8Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
CVE-2025-62774LOW3.1On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.
CVE-2025-62773LOW2.4Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
CVE-2025-62772LOW3.1On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
CVE-2025-62771HIGH7.5Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.
CVE-2025-22167MEDIUM6.5This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain ...
CVE-2025-61756HIGH7.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-62661MEDIUM6.9Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth...
CVE-2025-62641HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62592MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62591MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62590HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62589HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now