2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48240 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of ... |
| CVE-2025-48239 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product ... |
| CVE-2025-48238 | HIGH | 7.1 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit awcode-toolkit allows Stored XSS.This issue aff... |
| CVE-2025-48237 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist... |
| CVE-2025-48236 | HIGH | 8.5 | 0.4% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.ne... |
| CVE-2025-48235 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bogdan Bendziukov ... |
| CVE-2025-48234 | MEDIUM | 6.5 | 0.3% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul... |
| CVE-2025-48233 | HIGH | 7.1 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration affiliates-ma... |
| CVE-2025-48232 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons F... |
| CVE-2025-43714 | MEDIUM | 6.5 | 0.4% | May 19, 2025 | The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering the... |
| CVE-2025-3908 | MEDIUM | 6.2 | 0.2% | May 19, 2025 | The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlink... |
| CVE-2025-30072 | HIGH | 7.6 | 0.6% | May 19, 2025 | Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the prote... |
| CVE-2025-4935 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects s... |
| CVE-2025-4934 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability has been found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as ... |
| CVE-2025-44108 | MEDIUM | 4.8 | 0.3% | May 19, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the... |
| CVE-2025-28371 | MEDIUM | 6.5 | 0.4% | May 19, 2025 | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The de... |
| CVE-2025-4933 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability, which was classified as critical, was found in ponaravindb Hospital-Management-System 1.0. This affects... |
| CVE-2025-4932 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability, which was classified as critical, has been found in projectworlds Online Lawyer Management System 1.0. ... |
| CVE-2025-4931 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability classified as critical was found in projectworlds Online Lawyer Management System 1.0. Affected by this ... |
| CVE-2025-4930 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu... |
| CVE-2025-2099 | HIGH | 7.5 | 0.5% | May 19, 2025 | A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transfor... |
| CVE-2025-4929 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects som... |
| CVE-2025-4928 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in projectworlds Online Lawyer Management System 1.0. It has been declared as critical. This v... |
| CVE-2025-4927 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. Thi... |
| CVE-2025-4926 | HIGH | 7.2 | 0.4% | May 19, 2025 | A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is som... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now