2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67710MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67709MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67708MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67707MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...
CVE-2025-67706MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...
CVE-2025-67705MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67704MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67703MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-66148MEDIUM5.4Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrect...
CVE-2025-66146MEDIUM5.4Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Con...
CVE-2025-66145MEDIUM5.4Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Confi...
CVE-2025-66144MEDIUM5.4Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Con...
CVE-2025-28973MEDIUM6.5Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path T...
CVE-2025-66153MEDIUM5.4Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrect...
CVE-2025-66152MEDIUM5.4Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incor...
CVE-2025-66151MEDIUM5.4Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incor...
CVE-2025-66150MEDIUM5.4Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-66149MEDIUM5.4Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Con...
CVE-2025-34467MEDIUM4.3ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to ...
CVE-2025-62989MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked c...
CVE-2025-59135MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance P...
CVE-2025-49355MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibilit...
CVE-2025-49337MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashbo...
CVE-2025-66160MEDIUM5.4Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elemento...
CVE-2025-66159MEDIUM5.4Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now