2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41229 | HIGH | 8.2 | 0.6% | May 20, 2025 | VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 ... |
| CVE-2025-40635 | CRITICAL | 9.3 | 0.3% | May 20, 2025 | SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to... |
| CVE-2025-30193 | HIGH | 7.5 | 0.6% | May 20, 2025 | In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP conn... |
| CVE-2025-40634 | CRITICAL | 9.2 | 0.6% | May 20, 2025 | Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 rout... |
| CVE-2025-40633 | MEDIUM | 5.1 | 0.3% | May 20, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerab... |
| CVE-2025-37892 | HIGH | 7.8 | 0.2% | May 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob(... |
| CVE-2025-4951 | MEDIUM | 4.6 | 0.2% | May 20, 2025 | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in ... |
| CVE-2025-4322 | CRITICAL | 9.8 | 18.2% | May 20, 2025 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc... |
| CVE-2025-2929 | HIGH | 7.1 | 0.2% | May 20, 2025 | The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2025-4971 | HIGH | 8.5 | 0.5% | May 20, 2025 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execu... |
| CVE-2025-3079 | HIGH | 8.7 | 0.6% | May 20, 2025 | A passback vulnerability which relates to office/small office multifunction printers and laser printers. |
| CVE-2025-3078 | HIGH | 8.7 | 0.6% | May 20, 2025 | A passback vulnerability which relates to production printers and office multifunction printers. |
| CVE-2025-1308 | HIGH | 8.4 | 0.1% | May 19, 2025 | A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions. |
| CVE-2025-48340 | CRITICAL | 9.8 | 0.2% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privile... |
| CVE-2025-3223 | MEDIUM | 5.9 | 0.2% | May 19, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST... |
| CVE-2025-47949 | HIGH | 7.5 | 0.5% | May 19, 2025 | samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to ver... |
| CVE-2025-47946 | MEDIUM | 6.1 | 0.2% | May 19, 2025 | Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.... |
| CVE-2025-47944 | HIGH | 7.5 | 0.7% | May 19, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1... |
| CVE-2025-47935 | HIGH | 7.5 | 0.7% | May 19, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource ... |
| CVE-2025-46441 | MEDIUM | 5.3 | 0.3% | May 19, 2025 | Path Traversal: '.../...//' vulnerability in ctltwp Section Widget section-widget allows Path Traversal.This issue affec... |
| CVE-2025-39402 | CRITICAL | 9.9 | 0.3% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web... |
| CVE-2025-39401 | CRITICAL | 10 | 0.5% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web... |
| CVE-2025-39395 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apa... |
| CVE-2025-39393 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital ... |
| CVE-2025-39392 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now