2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-46421MEDIUM6.8A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio...
CVE-2025-46420MEDIUM6.5A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars...
CVE-2025-3832MEDIUM6.4The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al...
CVE-2025-3793MEDIUM4.2The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu...
CVE-2025-3280MEDIUM6.5The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio...
CVE-2025-2579MEDIUM6.4The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up ...
CVE-2025-2543MEDIUM6.4The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up...
CVE-2025-1284MEDIUM4.3The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable...
CVE-2025-41423MEDIUM4.3Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the ...
CVE-2025-32730MEDIUM6.8Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., ...
CVE-2025-1453MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could ...
CVE-2025-3435MEDIUM4.4The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote...
CVE-2025-1976MEDIUM6.7Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can ...
CVE-2025-46419MEDIUM5.9Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
CVE-2025-27581MEDIUM4.3NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t...
CVE-2025-25045MEDIUM4.3IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro...
CVE-2025-46400MEDIUM5.5In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input ...
CVE-2025-46399MEDIUM5.5A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu...
CVE-2025-46398MEDIUM5.5In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v...
CVE-2025-3907MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a...
CVE-2025-3902MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class...
CVE-2025-3901MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S...
CVE-2025-3900MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al...
CVE-2025-2772MEDIUM6.5BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner...
CVE-2025-2771MEDIUM5.3BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now