2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4223 | MEDIUM | 4.7 | 0.3% | May 24, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2025-5058 | CRITICAL | 9.8 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-4603 | CRITICAL | 9.1 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi... |
| CVE-2025-4602 | HIGH | 7.5 | 0.6% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u... |
| CVE-2025-4336 | CRITICAL | 9.8 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-5055 | MEDIUM | 4.4 | 0.2% | May 24, 2025 | The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-48756 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small... |
| CVE-2025-48755 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type). |
| CVE-2025-48754 | HIGH | 7.5 | 0.3% | May 24, 2025 | In the memory_pages crate 0.1.0 for Rust, division by zero can occur. |
| CVE-2025-48753 | CRITICAL | 9.8 | 0.2% | May 24, 2025 | In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. |
| CVE-2025-48752 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked. |
| CVE-2025-48751 | CRITICAL | 9.8 | 0.2% | May 24, 2025 | The process_lock crate 0.1.0 for Rust allows data races in unlock. |
| CVE-2025-3869 | MEDIUM | 6.1 | 0.3% | May 24, 2025 | The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9.... |
| CVE-2025-5119 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code o... |
| CVE-2025-48741 | MEDIUM | 6.8 | 0.3% | May 23, 2025 | A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5... |
| CVE-2025-48740 | MEDIUM | 5.9 | 0.2% | May 23, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 ... |
| CVE-2025-48739 | MEDIUM | 4.6 | 0.4% | May 23, 2025 | A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0... |
| CVE-2025-48738 | MEDIUM | 6.9 | 0.4% | May 23, 2025 | An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, an... |
| CVE-2025-48735 | MEDIUM | 4.3 | 0.3% | May 23, 2025 | A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230... |
| CVE-2025-46176 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotel... |
| CVE-2025-44998 | MEDIUM | 6.1 | 0.2% | May 23, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows... |
| CVE-2025-48378 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48377 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48376 | LOW | 2.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48375 | MEDIUM | 5.3 | 0.4% | May 23, 2025 | Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equiva... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now