2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4170 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr'... |
| CVE-2025-4168 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode... |
| CVE-2025-47229 | MEDIUM | 5.5 | 0.2% | May 3, 2025 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa... |
| CVE-2025-3918 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg... |
| CVE-2025-3779 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all ve... |
| CVE-2025-46723 | HIGH | 7.8 | 0.4% | May 2, 2025 | OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is... |
| CVE-2025-21572 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens thr... |
| CVE-2025-4218 | HIGH | 7.8 | 0.3% | May 2, 2025 | A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulne... |
| CVE-2025-4215 | LOW | 3.7 | 0.5% | May 2, 2025 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t... |
| CVE-2025-47226 | LOW | 3.3 | 1.1% | May 2, 2025 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. |
| CVE-2025-0782 | — | — | — | May 2, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-4214 | CRITICAL | 9.8 | 0.4% | May 2, 2025 | A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue af... |
| CVE-2025-4213 | CRITICAL | 9.8 | 0.3% | May 2, 2025 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulner... |
| CVE-2025-46332 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 ... |
| CVE-2025-45800 | CRITICAL | 9.8 | 0.7% | May 2, 2025 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the... |
| CVE-2025-3879 | HIGH | 8.8 | 0.4% | May 2, 2025 | Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued ... |
| CVE-2025-4210 | HIGH | 7.3 | 1.8% | May 2, 2025 | A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function Handl... |
| CVE-2025-4166 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in... |
| CVE-2025-44877 | CRITICAL | 9.8 | 2.0% | May 2, 2025 | Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via... |
| CVE-2025-44872 | CRITICAL | 9.8 | 2.0% | May 2, 2025 | Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via... |
| CVE-2025-44868 | CRITICAL | 9.8 | 2.6% | May 2, 2025 | Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.... |
| CVE-2025-3927 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t... |
| CVE-2025-37798 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_r... |
| CVE-2025-37797 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class h... |
| CVE-2025-1884 | HIGH | 7.8 | 0.2% | May 2, 2025 | Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now