2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1883 | HIGH | 7.8 | 0.2% | May 2, 2025 | Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS... |
| CVE-2025-4204 | HIGH | 7.5 | 0.3% | May 2, 2025 | The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versi... |
| CVE-2025-2605 | HIGH | 8.8 | 9.4% | May 2, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB... |
| CVE-2025-2488 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis In... |
| CVE-2025-2421 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Inj... |
| CVE-2025-1301 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Info... |
| CVE-2025-0427 | HIGH | 7.8 | 0.1% | May 2, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2025-0072 | HIGH | 7.8 | 0.3% | May 2, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-2812 | CRITICAL | 9.8 | 0.4% | May 2, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics... |
| CVE-2025-47201 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaSc... |
| CVE-2025-3514 | LOW | 3.5 | 0.2% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3513 | LOW | 3.5 | 0.3% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3488 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher short... |
| CVE-2025-3438 | HIGH | 7.3 | 0.3% | May 2, 2025 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege e... |
| CVE-2025-3858 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all version... |
| CVE-2025-3748 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu... |
| CVE-2025-3709 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attacker... |
| CVE-2025-3708 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-3707 | MEDIUM | 6.5 | 0.4% | May 2, 2025 | The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject... |
| CVE-2025-3510 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver... |
| CVE-2025-1327 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.... |
| CVE-2025-1326 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th... |
| CVE-2025-4179 | HIGH | 7.3 | 0.3% | May 2, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o... |
| CVE-2025-4177 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t... |
| CVE-2025-4131 | MEDIUM | 6.4 | 0.2% | May 2, 2025 | The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now