2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40775 | HIGH | 7.5 | 10.8% | May 21, 2025 | When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta... |
| CVE-2025-1421 | LOW | 2.4 | 0.2% | May 21, 2025 | Data provided in a request performed to the server while activating a new device are put in a database. Other high privi... |
| CVE-2025-1420 | LOW | 2.4 | 0.2% | May 21, 2025 | Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-p... |
| CVE-2025-1419 | LOW | 2.4 | 0.2% | May 21, 2025 | Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perfo... |
| CVE-2025-1418 | MEDIUM | 5.1 | 0.2% | May 21, 2025 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which cont... |
| CVE-2025-1417 | MEDIUM | 4.6 | 0.2% | May 21, 2025 | In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by... |
| CVE-2025-1416 | HIGH | 7 | 0.2% | May 21, 2025 | In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities res... |
| CVE-2025-4803 | HIGH | 7.2 | 0.6% | May 21, 2025 | The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection ... |
| CVE-2025-4611 | MEDIUM | 6.4 | 0.5% | May 21, 2025 | The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-4221 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader... |
| CVE-2025-4219 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all v... |
| CVE-2025-4217 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_yo... |
| CVE-2025-4105 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on ... |
| CVE-2025-48414 | MEDIUM | 6.5 | 0.3% | May 21, 2025 | There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts ... |
| CVE-2025-48413 | HIGH | 7.7 | 0.2% | May 21, 2025 | The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr... |
| CVE-2025-41232 | CRITICAL | 9.1 | 0.5% | May 21, 2025 | Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an autho... |
| CVE-2025-3781 | MEDIUM | 6.4 | 0.3% | May 21, 2025 | The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_don... |
| CVE-2025-3750 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ param... |
| CVE-2025-27804 | MEDIUM | 6.5 | 1.0% | May 21, 2025 | Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishi... |
| CVE-2025-27803 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network ac... |
| CVE-2025-1415 | MEDIUM | 5.1 | 0.2% | May 21, 2025 | A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Dev... |
| CVE-2025-1712 | HIGH | 8.8 | 0.7% | May 21, 2025 | Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat... |
| CVE-2025-4949 | MEDIUM | 5.3 | 1.1% | May 21, 2025 | In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the Amazo... |
| CVE-2025-4524 | CRITICAL | 9.8 | 9.1% | May 21, 2025 | The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-5013 | MEDIUM | 4.7 | 0.6% | May 21, 2025 | A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown par... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now