2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1454 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2025-1303 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2025-1289 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2025-1288 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2025-1286 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting... |
| CVE-2025-1033 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2025-0688 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ... |
| CVE-2025-0687 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ... |
| CVE-2025-0329 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou... |
| CVE-2025-4714 | CRITICAL | 9.8 | 0.5% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a... |
| CVE-2025-4713 | CRITICAL | 9.8 | 0.5% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som... |
| CVE-2025-4712 | CRITICAL | 9.8 | 0.5% | May 15, 2025 | A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit... |
| CVE-2025-32922 | HIGH | 7.1 | 0.1% | May 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This iss... |
| CVE-2025-30476 | HIGH | 7.5 | 0.4% | May 15, 2025 | Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated ... |
| CVE-2025-30475 | CRITICAL | 9.8 | 0.3% | May 15, 2025 | Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe... |
| CVE-2025-26481 | HIGH | 7.5 | 0.4% | May 15, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A ... |
| CVE-2025-4711 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects a... |
| CVE-2025-4710 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected ... |
| CVE-2025-4709 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerabi... |
| CVE-2025-47774 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t... |
| CVE-2025-47285 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `... |
| CVE-2025-47279 | LOW | 3.1 | 0.3% | May 15, 2025 | Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i... |
| CVE-2025-44110 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php. |
| CVE-2025-43853 | MEDIUM | 5.5 | 0.2% | May 15, 2025 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA... |
| CVE-2025-4708 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now