2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32401 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d... |
| CVE-2025-32400 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-32399 | HIGH | 7.5 | 0.5% | May 7, 2025 | An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t... |
| CVE-2025-32398 | HIGH | 7.5 | 0.3% | May 7, 2025 | A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices ... |
| CVE-2025-32397 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-32396 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-1400 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers... |
| CVE-2025-1399 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff... |
| CVE-2025-3766 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil... |
| CVE-2025-4335 | HIGH | 8.8 | 0.3% | May 7, 2025 | The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and... |
| CVE-2025-4220 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' ... |
| CVE-2025-4055 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s... |
| CVE-2025-4054 | MEDIUM | 6.1 | 0.4% | May 7, 2025 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights fu... |
| CVE-2025-3924 | MEDIUM | 5.3 | 0.3% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public... |
| CVE-2025-3921 | HIGH | 8.2 | 0.4% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-3860 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in al... |
| CVE-2025-3853 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.... |
| CVE-2025-3852 | HIGH | 8.8 | 0.4% | May 7, 2025 | The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.... |
| CVE-2025-3851 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire... |
| CVE-2025-3844 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to... |
| CVE-2025-2821 | MEDIUM | 5.3 | 0.3% | May 7, 2025 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-3218 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation ... |
| CVE-2025-0856 | HIGH | 7.3 | 0.2% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ... |
| CVE-2025-0855 | CRITICAL | 9.8 | 0.5% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ... |
| CVE-2025-4372 | HIGH | 8.8 | 0.5% | May 6, 2025 | Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now