2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4579 | HIGH | 7.2 | 0.3% | May 15, 2025 | The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and... |
| CVE-2025-47783 | MEDIUM | 6.1 | 0.5% | May 14, 2025 | Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an at... |
| CVE-2025-46836 | MEDIUM | 6.6 | 0.2% | May 14, 2025 | net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operatin... |
| CVE-2025-32421 | LOW | 3.7 | 0.7% | May 14, 2025 | Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-... |
| CVE-2025-29691 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29690 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29689 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29688 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29686 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-47889 | CRITICAL | 9.8 | 0.6% | May 14, 2025 | In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" ... |
| CVE-2025-47888 | MEDIUM | 5.9 | 0.2% | May 14, 2025 | Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne... |
| CVE-2025-47887 | MEDIUM | 4.3 | 0.3% | May 14, 2025 | Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers wit... |
| CVE-2025-47886 | MEDIUM | 4.3 | 0.2% | May 14, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earl... |
| CVE-2025-47885 | HIGH | 8.8 | 0.5% | May 14, 2025 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Hea... |
| CVE-2025-47884 | CRITICAL | 9.1 | 0.6% | May 14, 2025 | In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentiall... |
| CVE-2025-44879 | HIGH | 7.5 | 0.4% | May 14, 2025 | WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerabi... |
| CVE-2025-44024 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exist... |
| CVE-2025-27891 | CRITICAL | 9.1 | 0.4% | May 14, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-26783 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330,... |
| CVE-2025-32363 | CRITICAL | 9.8 | 0.8% | May 14, 2025 | mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization... |
| CVE-2025-25370 | MEDIUM | 4.6 | 0.2% | May 14, 2025 | An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain... |
| CVE-2025-4641 | CRITICAL | 9.3 | 0.5% | May 14, 2025 | Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W... |
| CVE-2025-4640 | HIGH | 8.3 | 0.3% | May 14, 2025 | Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default... |
| CVE-2025-33104 | HIGH | 7.6 | 0.2% | May 14, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2025-2900 | HIGH | 7.5 | 0.2% | May 14, 2025 | IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now