2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4249 | CRITICAL | 9.8 | 0.4% | May 4, 2025 | A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-4248 | CRITICAL | 9.8 | 0.4% | May 4, 2025 | A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by th... |
| CVE-2025-4247 | HIGH | 8.8 | 0.4% | May 4, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is... |
| CVE-2025-47245 | HIGH | 8.1 | 0.4% | May 4, 2025 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. |
| CVE-2025-47244 | HIGH | 7.3 | 0.4% | May 3, 2025 | Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, ... |
| CVE-2025-47241 | MEDIUM | 4 | 0.5% | May 3, 2025 | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be pla... |
| CVE-2025-4244 | HIGH | 8.8 | 0.4% | May 3, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This af... |
| CVE-2025-4243 | HIGH | 8.8 | 0.4% | May 3, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Af... |
| CVE-2025-4242 | CRITICAL | 9.8 | 0.3% | May 3, 2025 | A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vul... |
| CVE-2025-1838 | MEDIUM | 6.5 | 0.3% | May 3, 2025 | IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user ... |
| CVE-2025-4241 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Af... |
| CVE-2025-4240 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown proc... |
| CVE-2025-4239 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow... |
| CVE-2025-4238 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of... |
| CVE-2025-1495 | MEDIUM | 4.3 | 0.2% | May 3, 2025 | IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to mis... |
| CVE-2025-4237 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f... |
| CVE-2025-4236 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a... |
| CVE-2025-37799 | MEDIUM | 5.5 | 0.2% | May 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix malformed packet sizing in vmxnet3_pro... |
| CVE-2025-4226 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This aff... |
| CVE-2025-3815 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up... |
| CVE-2025-4222 | MEDIUM | 5.9 | 0.4% | May 3, 2025 | The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-4199 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-4198 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3... |
| CVE-2025-4188 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2025-4172 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now