2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4723 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne... |
| CVE-2025-4722 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un... |
| CVE-2025-47287 | HIGH | 7.5 | 0.7% | May 15, 2025 | Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser enc... |
| CVE-2025-47275 | CRITICAL | 9.1 | 0.5% | May 15, 2025 | Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior t... |
| CVE-2025-4721 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff... |
| CVE-2025-4720 | MEDIUM | 5.4 | 0.5% | May 15, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This... |
| CVE-2025-4719 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-4718 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-47929 | LOW | 2.1 | 0.3% | May 15, 2025 | DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scr... |
| CVE-2025-1138 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in f... |
| CVE-2025-4717 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affect... |
| CVE-2025-4716 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this i... |
| CVE-2025-4715 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by thi... |
| CVE-2025-47928 | CRITICAL | 9.1 | 0.4% | May 15, 2025 | Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_... |
| CVE-2025-47789 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attac... |
| CVE-2025-47788 | CRITICAL | 9.4 | 0.4% | May 15, 2025 | Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$tar... |
| CVE-2025-47787 | CRITICAL | 9.8 | 0.6% | May 15, 2025 | Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability.... |
| CVE-2025-47786 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that all... |
| CVE-2025-47785 | HIGH | 8.8 | 0.6% | May 15, 2025 | Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the... |
| CVE-2025-47784 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user ... |
| CVE-2025-47161 | HIGH | 7.8 | 0.7% | May 15, 2025 | Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. |
| CVE-2025-46834 | MEDIUM | 6.6 | 0.3% | May 15, 2025 | Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the ... |
| CVE-2025-2248 | MEDIUM | 5.4 | 0.1% | May 15, 2025 | The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement... |
| CVE-2025-2247 | MEDIUM | 5.4 | 0.1% | May 15, 2025 | The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2025-2203 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statemen... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now