2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4501 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects ... |
| CVE-2025-4500 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected... |
| CVE-2025-4499 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by thi... |
| CVE-2025-3878 | MEDIUM | 5.4 | 0.2% | May 10, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-3876 | HIGH | 8.8 | 0.4% | May 10, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insuff... |
| CVE-2025-4498 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is th... |
| CVE-2025-2158 | HIGH | 8.8 | 0.7% | May 10, 2025 | The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L... |
| CVE-2025-4497 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue af... |
| CVE-2025-2944 | MEDIUM | 6.4 | 0.4% | May 10, 2025 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button an... |
| CVE-2025-4496 | CRITICAL | 9.8 | 0.9% | May 10, 2025 | A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It ha... |
| CVE-2025-47770 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47769 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47768 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47767 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47766 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47765 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47764 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47763 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-47762 | — | — | — | May 10, 2025 | Rejected reason: Not used |
| CVE-2025-1137 | HIGH | 8.8 | 0.3% | May 10, 2025 | IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil... |
| CVE-2025-4495 | MEDIUM | 5.4 | 0.3% | May 10, 2025 | A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability i... |
| CVE-2025-47424 | HIGH | 7.1 | 0.1% | May 9, 2025 | Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, ... |
| CVE-2025-3794 | MEDIUM | 5.4 | 0.3% | May 9, 2025 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2025-4494 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin... |
| CVE-2025-4492 | CRITICAL | 9.8 | 0.5% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This iss... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now