2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4827 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615.... |
| CVE-2025-4101 | MEDIUM | 4.3 | 0.2% | May 17, 2025 | The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss... |
| CVE-2025-48187 | CRITICAL | 9.8 | 0.5% | May 17, 2025 | RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against ... |
| CVE-2025-4669 | MEDIUM | 5.4 | 0.3% | May 17, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod... |
| CVE-2025-3888 | MEDIUM | 5.4 | 0.3% | May 17, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi... |
| CVE-2025-3527 | MEDIUM | 5.4 | 0.2% | May 17, 2025 | The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2025-4826 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.... |
| CVE-2025-4825 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulner... |
| CVE-2025-4824 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This a... |
| CVE-2025-4823 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Aff... |
| CVE-2025-4610 | MEDIUM | 6.4 | 0.3% | May 17, 2025 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme... |
| CVE-2025-4819 | LOW | 3.1 | 0.4% | May 17, 2025 | A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of th... |
| CVE-2025-4391 | CRITICAL | 9.8 | 0.6% | May 17, 2025 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v... |
| CVE-2025-4389 | CRITICAL | 9.8 | 0.9% | May 17, 2025 | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to mis... |
| CVE-2025-4190 | HIGH | 7.2 | 0.5% | May 17, 2025 | The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege us... |
| CVE-2025-3812 | HIGH | 8.1 | 0.5% | May 17, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-4818 | CRITICAL | 9.8 | 0.4% | May 17, 2025 | A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been rated as critical. This issue a... |
| CVE-2025-4817 | CRITICAL | 9.8 | 0.4% | May 17, 2025 | A vulnerability was found in Sourcecodester Doctor's Appointment System 1.0. It has been declared as critical. This vuln... |
| CVE-2025-4816 | CRITICAL | 9.8 | 0.4% | May 17, 2025 | A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This af... |
| CVE-2025-4194 | MEDIUM | 6.1 | 0.1% | May 17, 2025 | The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-4189 | MEDIUM | 6.1 | 0.1% | May 17, 2025 | The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-4815 | CRITICAL | 9.8 | 0.4% | May 17, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-4814 | CRITICAL | 9.8 | 0.4% | May 17, 2025 | A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-1706 | HIGH | 7.5 | 0.4% | May 17, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern... |
| CVE-2025-4813 | CRITICAL | 9.8 | 0.5% | May 16, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Human Metapneumovirus Testing Management Syst... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now