2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43860 | HIGH | 7.6 | 3.4% | May 23, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-... |
| CVE-2025-32967 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. A logging overs... |
| CVE-2025-32794 | HIGH | 7.6 | 4.0% | May 23, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-... |
| CVE-2025-24917 | HIGH | 7.8 | 0.2% | May 23, 2025 | In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could ... |
| CVE-2025-24916 | HIGH | 7.8 | 0.1% | May 23, 2025 | When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions pr... |
| CVE-2025-5114 | CRITICAL | 9.1 | 0.4% | May 23, 2025 | A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affect... |
| CVE-2025-5112 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o... |
| CVE-2025-5111 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is... |
| CVE-2025-5110 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-3580 | MEDIUM | 5.5 | 0.4% | May 23, 2025 | An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently dele... |
| CVE-2025-5109 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th... |
| CVE-2025-5108 | CRITICAL | 9.8 | 0.3% | May 23, 2025 | A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo... |
| CVE-2025-5107 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown co... |
| CVE-2025-48292 | HIGH | 8.1 | 0.4% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48289 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issu... |
| CVE-2025-48287 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Inject... |
| CVE-2025-48286 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restau... |
| CVE-2025-48283 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support M... |
| CVE-2025-48275 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-48273 | HIGH | 7.5 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Porta... |
| CVE-2025-48271 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-48245 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick C... |
| CVE-2025-48241 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg... |
| CVE-2025-47690 | HIGH | 8.8 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allow... |
| CVE-2025-47687 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now