2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4913 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. Affected by th... |
| CVE-2025-4477 | HIGH | 8.6 | 0.4% | May 19, 2025 | The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with int... |
| CVE-2025-2561 | MEDIUM | 4.8 | 0.2% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-2560 | MEDIUM | 4.8 | 0.2% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-2524 | MEDIUM | 4.8 | 0.3% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-1627 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them ... |
| CVE-2025-1626 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before output... |
| CVE-2025-1625 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputti... |
| CVE-2025-4912 | CRITICAL | 9.1 | 0.7% | May 19, 2025 | A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affect... |
| CVE-2025-4911 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unk... |
| CVE-2025-2892 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-4910 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue af... |
| CVE-2025-4909 | HIGH | 7.3 | 0.4% | May 19, 2025 | A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerabi... |
| CVE-2025-4908 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an un... |
| CVE-2025-4907 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by thi... |
| CVE-2025-4906 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability was found in PHPGurukul Notice Board System 1.0. It has been classified as critical. Affected is an unkn... |
| CVE-2025-4905 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the f... |
| CVE-2025-23167 | MEDIUM | 6.5 | 0.5% | May 19, 2025 | A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required... |
| CVE-2025-23166 | HIGH | 7.5 | 0.8% | May 19, 2025 | The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executi... |
| CVE-2025-23165 | LOW | 3.7 | 0.5% | May 19, 2025 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path... |
| CVE-2025-23164 | MEDIUM | 4.4 | 0.3% | May 19, 2025 | A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the re... |
| CVE-2025-23123 | CRITICAL | 10 | 1.1% | May 19, 2025 | A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap... |
| CVE-2025-23122 | — | — | — | May 19, 2025 | Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23165. |
| CVE-2025-4904 | MEDIUM | 5.3 | 1.0% | May 19, 2025 | A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. This vulnerabilit... |
| CVE-2025-4903 | HIGH | 7.5 | 0.6% | May 19, 2025 | A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now