2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2571 | MEDIUM | 4.2 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c... |
| CVE-2025-1792 | LOW | 3.1 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for g... |
| CVE-2025-0602 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DE... |
| CVE-2025-4598 | MEDIUM | 4.7 | 0.8% | May 30, 2025 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace... |
| CVE-2025-48331 | HIGH | 7.5 | 0.3% | May 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter wooc... |
| CVE-2025-4433 | HIGH | 8.8 | 0.5% | May 30, 2025 | Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrativ... |
| CVE-2025-40909 | MEDIUM | 5.9 | 0.4% | May 30, 2025 | Perl threads have a working directory race condition where file operations may target unintended paths. If a directory ... |
| CVE-2025-2500 | CRITICAL | 9.1 | 0.3% | May 30, 2025 | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an... |
| CVE-2025-1484 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite... |
| CVE-2025-5190 | HIGH | 8.8 | 0.4% | May 30, 2025 | The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is... |
| CVE-2025-4944 | MEDIUM | 6.4 | 0.2% | May 30, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-4597 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-1763 | HIGH | 8.7 | 0.5% | May 30, 2025 | An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass... |
| CVE-2025-5235 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ paramete... |
| CVE-2025-5142 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-4636 | HIGH | 7.8 | 0.1% | May 30, 2025 | Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co... |
| CVE-2025-4635 | MEDIUM | 6.6 | 0.3% | May 30, 2025 | A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to ... |
| CVE-2025-4634 | MEDIUM | 4.1 | 0.2% | May 30, 2025 | The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privile... |
| CVE-2025-4633 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor... |
| CVE-2025-48912 | MEDIUM | 6.5 | 0.6% | May 30, 2025 | An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injec... |
| CVE-2025-48334 | MEDIUM | 4.3 | 0.2% | May 30, 2025 | Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocom... |
| CVE-2025-5236 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ par... |
| CVE-2025-4431 | MEDIUM | 4.3 | 0.3% | May 30, 2025 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2025-4943 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-... |
| CVE-2025-48936 | HIGH | 8.8 | 0.4% | May 30, 2025 | Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now