2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4707 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects... |
| CVE-2025-4706 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnera... |
| CVE-2025-47580 | CRITICAL | 9.8 | 0.2% | May 15, 2025 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Con... |
| CVE-2025-30421 | HIGH | 7.8 | 0.2% | May 15, 2025 | There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when... |
| CVE-2025-30420 | HIGH | 7.8 | 0.2% | May 15, 2025 | There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolE... |
| CVE-2025-30419 | HIGH | 7.8 | 0.2% | May 15, 2025 | There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the Symb... |
| CVE-2025-30418 | HIGH | 7.8 | 0.2% | May 15, 2025 | There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in N... |
| CVE-2025-30417 | HIGH | 7.8 | 0.2% | May 15, 2025 | There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the Symbol... |
| CVE-2025-1647 | MEDIUM | 5.6 | 0.3% | May 15, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap a... |
| CVE-2025-4705 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This... |
| CVE-2025-4704 | HIGH | 7.3 | 0.4% | May 15, 2025 | A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t... |
| CVE-2025-4703 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected... |
| CVE-2025-48051 | MEDIUM | 6.1 | 0.4% | May 15, 2025 | powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern i... |
| CVE-2025-48050 | HIGH | 7.5 | 0.4% | May 15, 2025 | In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curren... |
| CVE-2025-3440 | MEDIUM | 5.5 | 0.2% | May 15, 2025 | IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to ... |
| CVE-2025-2570 | LOW | 2.7 | 0.3% | May 15, 2025 | Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have... |
| CVE-2025-2527 | MEDIUM | 4.3 | 0.3% | May 15, 2025 | Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing gr... |
| CVE-2025-4702 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affec... |
| CVE-2025-4701 | MEDIUM | 5.3 | 0.2% | May 15, 2025 | A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue... |
| CVE-2025-46053 | MEDIUM | 5.1 | 0.2% | May 15, 2025 | A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive... |
| CVE-2025-44185 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_... |
| CVE-2025-4699 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical was found in PHPGurukul Apartment Visitors Management System 1.0. This vulnerabil... |
| CVE-2025-4698 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unk... |
| CVE-2025-4516 | MEDIUM | 5.9 | 0.2% | May 15, 2025 | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using t... |
| CVE-2025-46052 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now