2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44183 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via t... |
| CVE-2025-44182 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modeln... |
| CVE-2025-44181 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via... |
| CVE-2025-44180 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={bra... |
| CVE-2025-4697 | CRITICAL | 9.8 | 0.4% | May 15, 2025 | A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this... |
| CVE-2025-4696 | HIGH | 8.8 | 0.4% | May 15, 2025 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Af... |
| CVE-2025-4695 | HIGH | 8.8 | 0.3% | May 15, 2025 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. ... |
| CVE-2025-4762 | LOW | 2 | 0.3% | May 15, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.... |
| CVE-2025-4564 | CRITICAL | 9.8 | 0.9% | May 15, 2025 | The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien... |
| CVE-2025-3446 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct pe... |
| CVE-2025-31947 | MEDIUM | 5.3 | 0.3% | May 15, 2025 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users f... |
| CVE-2025-32738 | MEDIUM | 6.9 | 0.4% | May 15, 2025 | Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware... |
| CVE-2025-32002 | CRITICAL | 9.8 | 1.7% | May 15, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA netw... |
| CVE-2025-4737 | MEDIUM | 6.2 | 0.1% | May 15, 2025 | Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of... |
| CVE-2025-27525 | LOW | 3.9 | 0.1% | May 15, 2025 | Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a... |
| CVE-2025-27524 | MEDIUM | 5.3 | 0.1% | May 15, 2025 | Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affect... |
| CVE-2025-27523 | HIGH | 8.7 | 0.3% | May 15, 2025 | XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Des... |
| CVE-2025-48027 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolutio... |
| CVE-2025-3742 | MEDIUM | 6.8 | 0.5% | May 15, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes befo... |
| CVE-2025-48024 | MEDIUM | 5 | 0.3% | May 15, 2025 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1... |
| CVE-2025-3053 | HIGH | 8.8 | 0.9% | May 15, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod... |
| CVE-2025-4591 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcod... |
| CVE-2025-4589 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in... |
| CVE-2025-4126 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a... |
| CVE-2025-3917 | CRITICAL | 9.8 | 0.7% | May 15, 2025 | The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now