2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46421 | MEDIUM | 6.8 | 0.5% | Apr 24, 2025 | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio... |
| CVE-2025-46420 | MEDIUM | 6.5 | 0.5% | Apr 24, 2025 | A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars... |
| CVE-2025-3832 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al... |
| CVE-2025-3793 | MEDIUM | 4.2 | 0.2% | Apr 24, 2025 | The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu... |
| CVE-2025-3280 | MEDIUM | 6.5 | 0.3% | Apr 24, 2025 | The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio... |
| CVE-2025-2579 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up ... |
| CVE-2025-2543 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2025-1284 | MEDIUM | 4.3 | 0.2% | Apr 24, 2025 | The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable... |
| CVE-2025-41423 | MEDIUM | 4.3 | 0.2% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the ... |
| CVE-2025-32730 | MEDIUM | 6.8 | 0.1% | Apr 24, 2025 | Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., ... |
| CVE-2025-1453 | MEDIUM | 4.8 | 0.2% | Apr 24, 2025 | The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could ... |
| CVE-2025-3435 | MEDIUM | 4.4 | 0.2% | Apr 24, 2025 | The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote... |
| CVE-2025-1976 | MEDIUM | 6.7 | 0.7% | Apr 24, 2025 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can ... |
| CVE-2025-46419 | MEDIUM | 5.9 | 0.3% | Apr 24, 2025 | Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet. |
| CVE-2025-27581 | MEDIUM | 4.3 | 0.3% | Apr 24, 2025 | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t... |
| CVE-2025-25045 | MEDIUM | 4.3 | 0.2% | Apr 23, 2025 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro... |
| CVE-2025-46400 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input ... |
| CVE-2025-46399 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu... |
| CVE-2025-46398 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v... |
| CVE-2025-3907 | MEDIUM | 4.3 | 0.1% | Apr 23, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a... |
| CVE-2025-3902 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class... |
| CVE-2025-3901 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S... |
| CVE-2025-3900 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al... |
| CVE-2025-2772 | MEDIUM | 6.5 | 0.4% | Apr 23, 2025 | BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner... |
| CVE-2025-2771 | MEDIUM | 5.3 | 0.7% | Apr 23, 2025 | BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now