2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3890 | MEDIUM | 5.4 | 0.2% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w... |
| CVE-2025-3889 | MEDIUM | 5.3 | 0.3% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2025-3874 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2025-1529 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v... |
| CVE-2025-4162 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability classified as critical was found in PCMan FTP Server up to 2.0.7. This vulnerability affects unknown cod... |
| CVE-2025-4161 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server up to 2.0.7. This affects an unknown part of t... |
| CVE-2025-27007 | CRITICAL | 9.8 | 50.2% | May 1, 2025 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This i... |
| CVE-2025-4160 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been rated as critical. Affected by this issue is some... |
| CVE-2025-4159 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerabil... |
| CVE-2025-4158 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been classified as critical. Affected is an unknown fu... |
| CVE-2025-4157 | HIGH | 8.8 | 0.3% | May 1, 2025 | A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unkn... |
| CVE-2025-4156 | HIGH | 8.8 | 0.3% | May 1, 2025 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe... |
| CVE-2025-4155 | HIGH | 8.8 | 0.3% | May 1, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn... |
| CVE-2025-47154 | CRITICAL | 9 | 0.6% | May 1, 2025 | LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-a... |
| CVE-2025-4154 | HIGH | 8.8 | 0.3% | May 1, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affect... |
| CVE-2025-4153 | CRITICAL | 9.8 | 0.4% | May 1, 2025 | A vulnerability classified as critical was found in PHPGurukul Park Ticketing Management System 2.0. Affected by this vu... |
| CVE-2025-4100 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma... |
| CVE-2025-47153 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_2... |
| CVE-2025-3521 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vul... |
| CVE-2025-4152 | CRITICAL | 9.8 | 0.3% | May 1, 2025 | A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an ... |
| CVE-2025-4151 | CRITICAL | 9.8 | 0.4% | May 1, 2025 | A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue a... |
| CVE-2025-3504 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-3503 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-3502 | MEDIUM | 4.8 | 0.3% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-4150 | CRITICAL | 9.8 | 1.3% | May 1, 2025 | A vulnerability was found in Netgear EX6200 1.0.3.94. It has been declared as critical. This vulnerability affects the f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now