2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46599 | MEDIUM | 6.8 | 0.4% | Apr 25, 2025 | CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that,... |
| CVE-2025-3775 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2025-3752 | MEDIUM | 6.4 | 0.3% | Apr 25, 2025 | The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-46595 | MEDIUM | 6.4 | 0.2% | Apr 25, 2025 | An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to ... |
| CVE-2025-46547 | MEDIUM | 6.1 | 0.1% | Apr 25, 2025 | In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an a... |
| CVE-2025-46546 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This ... |
| CVE-2025-46545 | MEDIUM | 4.8 | 0.2% | Apr 25, 2025 | In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an adm... |
| CVE-2025-46544 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles. |
| CVE-2025-43865 | HIGH | 8.2 | 0.7% | Apr 25, 2025 | React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re... |
| CVE-2025-43864 | HIGH | 7.5 | 23.6% | Apr 25, 2025 | React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an app... |
| CVE-2025-3606 | HIGH | 8.7 | 0.3% | Apr 25, 2025 | Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s... |
| CVE-2025-2185 | HIGH | 8.5 | 0.3% | Apr 25, 2025 | ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se... |
| CVE-2025-46275 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator accou... |
| CVE-2025-46274 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en... |
| CVE-2025-46273 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges... |
| CVE-2025-46272 | CRITICAL | 9.3 | 1.3% | Apr 24, 2025 | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke... |
| CVE-2025-46271 | CRITICAL | 9.3 | 2.0% | Apr 24, 2025 | UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu... |
| CVE-2025-3749 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all... |
| CVE-2025-1294 | HIGH | 7.2 | 0.3% | Apr 24, 2025 | The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up ... |
| CVE-2025-43861 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to... |
| CVE-2025-29529 | MEDIUM | 6.5 | 0.3% | Apr 24, 2025 | ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via th... |
| CVE-2025-25777 | HIGH | 8 | 0.2% | Apr 24, 2025 | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user p... |
| CVE-2025-26382 | CRITICAL | 9.3 | 0.5% | Apr 24, 2025 | Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue |
| CVE-2025-43859 | CRITICAL | 9.1 | 0.5% | Apr 24, 2025 | h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ... |
| CVE-2025-43858 | CRITICAL | 9.2 | 0.2% | Apr 24, 2025 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now