2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46726 | CRITICAL | 9.1 | 0.5% | May 5, 2025 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM applicati... |
| CVE-2025-45618 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all... |
| CVE-2025-45617 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit... |
| CVE-2025-45616 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a craft... |
| CVE-2025-45615 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights... |
| CVE-2025-45614 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information... |
| CVE-2025-45613 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati... |
| CVE-2025-45612 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. |
| CVE-2025-45611 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via ... |
| CVE-2025-45610 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen... |
| CVE-2025-45609 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf... |
| CVE-2025-45608 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens... |
| CVE-2025-45607 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request. |
| CVE-2025-1909 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,... |
| CVE-2025-4318 | CRITICAL | 9 | 1.0% | May 5, 2025 | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input valida... |
| CVE-2025-4283 | CRITICAL | 9.8 | 0.5% | May 5, 2025 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue... |
| CVE-2025-4279 | HIGH | 8.8 | 0.6% | May 5, 2025 | The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-46720 | MEDIUM | 4.3 | 0.2% | May 5, 2025 | Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b... |
| CVE-2025-46719 | MEDIUM | 5.4 | 0.4% | May 5, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.... |
| CVE-2025-46571 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.... |
| CVE-2025-46559 | HIGH | 7.5 | 0.4% | May 5, 2025 | Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m... |
| CVE-2025-46553 | MEDIUM | 6.1 | 0.2% | May 5, 2025 | @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1... |
| CVE-2025-46340 | MEDIUM | 5.4 | 0.2% | May 5, 2025 | Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du... |
| CVE-2025-46335 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo... |
| CVE-2025-43852 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now