2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-44183MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via t...
CVE-2025-44182MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modeln...
CVE-2025-44181MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via...
CVE-2025-44180MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={bra...
CVE-2025-4697CRITICAL9.8A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this...
CVE-2025-4696HIGH8.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Af...
CVE-2025-4695HIGH8.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. ...
CVE-2025-4762LOW2Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1....
CVE-2025-4564CRITICAL9.8The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien...
CVE-2025-3446MEDIUM4.3Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct pe...
CVE-2025-31947MEDIUM5.3Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users f...
CVE-2025-32738MEDIUM6.9Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware...
CVE-2025-32002CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA netw...
CVE-2025-4737MEDIUM6.2Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of...
CVE-2025-27525LOW3.9Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a...
CVE-2025-27524MEDIUM5.3Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affect...
CVE-2025-27523HIGH8.7XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Des...
CVE-2025-48027MEDIUM5.4The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolutio...
CVE-2025-3742MEDIUM6.8The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes befo...
CVE-2025-48024MEDIUM5In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1...
CVE-2025-3053HIGH8.8The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod...
CVE-2025-4591MEDIUM6.4The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcod...
CVE-2025-4589MEDIUM6.4The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in...
CVE-2025-4126MEDIUM6.4The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a...
CVE-2025-3917CRITICAL9.8The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now