2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5286 | MEDIUM | 6.4 | 0.3% | May 29, 2025 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ pa... |
| CVE-2025-5122 | MEDIUM | 6.4 | 0.3% | May 29, 2025 | The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all v... |
| CVE-2025-4687 | HIGH | 7.2 | 0.4% | May 29, 2025 | In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the in... |
| CVE-2025-4670 | MEDIUM | 5.4 | 0.3% | May 29, 2025 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored... |
| CVE-2025-27151 | CRITICAL | 9.8 | 0.8% | May 29, 2025 | Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st... |
| CVE-2025-5276 | HIGH | 7.4 | 0.3% | May 29, 2025 | Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the... |
| CVE-2025-5273 | MEDIUM | 6.9 | 0.3% | May 29, 2025 | Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa... |
| CVE-2025-4583 | MEDIUM | 5.4 | 0.2% | May 29, 2025 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-3755 | CRITICAL | 9.1 | 0.7% | May 29, 2025 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation ME... |
| CVE-2025-27706 | LOW | 3.4 | 0.2% | May 28, 2025 | CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to ver... |
| CVE-2025-27703 | MEDIUM | 6 | 0.3% | May 28, 2025 | CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to ver... |
| CVE-2025-27702 | MEDIUM | 4.9 | 0.3% | May 28, 2025 | CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers... |
| CVE-2025-5256 | MEDIUM | 5.4 | 0.2% | May 28, 2025 | SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability... |
| CVE-2025-48749 | CRITICAL | 9.1 | 0.4% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Info... |
| CVE-2025-48747 | MEDIUM | 5 | 0.2% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor... |
| CVE-2025-47748 | MEDIUM | 5.3 | 0.3% | May 28, 2025 | Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password. |
| CVE-2025-32803 | MEDIUM | 4 | 0.2% | May 28, 2025 | In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, ... |
| CVE-2025-31501 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. |
| CVE-2025-31500 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. |
| CVE-2025-30087 | MEDIUM | 6.1 | 0.3% | May 28, 2025 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete... |
| CVE-2025-1461 | MEDIUM | 5.6 | 0.3% | May 28, 2025 | Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsa... |
| CVE-2025-5257 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u... |
| CVE-2025-48931 | MEDIUM | 5.5 | 0.1% | May 28, 2025 | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibiliti... |
| CVE-2025-48930 | MEDIUM | 5.3 | 0.1% | May 28, 2025 | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content ma... |
| CVE-2025-48929 | CRITICAL | 9.8 | 0.3% | May 28, 2025 | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now