2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45513 | CRITICAL | 9.8 | 0.5% | May 9, 2025 | Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter. |
| CVE-2025-28203 | HIGH | 8.8 | 1.1% | May 9, 2025 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. |
| CVE-2025-28202 | HIGH | 8.8 | 0.5% | May 9, 2025 | Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services witho... |
| CVE-2025-28201 | MEDIUM | 6.8 | 0.4% | May 9, 2025 | An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain ... |
| CVE-2025-28200 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits o... |
| CVE-2025-45887 | CRITICAL | 9.1 | 0.4% | May 9, 2025 | Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. |
| CVE-2025-45885 | CRITICAL | 9.8 | 0.4% | May 9, 2025 | PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att... |
| CVE-2025-4382 | MEDIUM | 5.9 | 0.4% | May 9, 2025 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB... |
| CVE-2025-4206 | HIGH | 7.2 | 1.3% | May 9, 2025 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner... |
| CVE-2025-3897 | MEDIUM | 5.9 | 0.6% | May 9, 2025 | The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 vi... |
| CVE-2025-3528 | HIGH | 8.2 | 0.2% | May 9, 2025 | A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has... |
| CVE-2025-1087 | CRITICAL | 9.3 | 1.0% | May 9, 2025 | Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to exe... |
| CVE-2025-46392 | MEDIUM | 6.5 | 1.7% | May 9, 2025 | Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Ap... |
| CVE-2025-4403 | CRITICAL | 9.8 | 1.8% | May 9, 2025 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a... |
| CVE-2025-3949 | MEDIUM | 4.3 | 0.6% | May 9, 2025 | The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor... |
| CVE-2025-4472 | HIGH | 7.8 | 0.4% | May 9, 2025 | A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical.... |
| CVE-2025-4471 | HIGH | 7.8 | 0.3% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0.... |
| CVE-2025-4470 | MEDIUM | 5.4 | 0.5% | May 9, 2025 | A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by t... |
| CVE-2025-4469 | MEDIUM | 5.4 | 0.5% | May 9, 2025 | A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected... |
| CVE-2025-4468 | CRITICAL | 9.8 | 0.9% | May 9, 2025 | A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This iss... |
| CVE-2025-4467 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been declared as critical. This ... |
| CVE-2025-3605 | CRITICAL | 9.8 | 6.4% | May 9, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2025-3455 | HIGH | 8.8 | 1.2% | May 9, 2025 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized... |
| CVE-2025-37889 | MEDIUM | 5.5 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Consistently treat platform_max as contr... |
| CVE-2025-37888 | MEDIUM | 5.5 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now