2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32044 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—i... |
| CVE-2025-28076 | MEDIUM | 6.5 | 0.3% | Apr 25, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated at... |
| CVE-2025-3634 | MEDIUM | 4.3 | 0.2% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completin... |
| CVE-2025-28354 | MEDIUM | 6.5 | 0.5% | Apr 25, 2025 | An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a ... |
| CVE-2025-3912 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-2986 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged... |
| CVE-2025-2470 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, ... |
| CVE-2025-1565 | HIGH | 7.5 | 0.5% | Apr 25, 2025 | The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v... |
| CVE-2025-3870 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-1279 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg... |
| CVE-2025-46535 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly C... |
| CVE-2025-46482 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Qui... |
| CVE-2025-46617 | HIGH | 7.2 | 0.3% | Apr 25, 2025 | Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification... |
| CVE-2025-46616 | CRITICAL | 9.9 | 0.6% | Apr 25, 2025 | Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. T... |
| CVE-2025-3868 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'... |
| CVE-2025-3867 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-3866 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-3743 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to... |
| CVE-2025-2238 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to... |
| CVE-2025-46613 | HIGH | 7.5 | 0.2% | Apr 25, 2025 | OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after... |
| CVE-2025-3923 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2025-3861 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modifi... |
| CVE-2025-3511 | HIGH | 7.5 | 0.9% | Apr 25, 2025 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remot... |
| CVE-2025-2580 | MEDIUM | 4.9 | 0.2% | Apr 25, 2025 | The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a... |
| CVE-2025-0671 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now