2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2579 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up ... |
| CVE-2025-2543 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2025-1284 | MEDIUM | 4.3 | 0.2% | Apr 24, 2025 | The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable... |
| CVE-2025-1908 | HIGH | 7.7 | 0.3% | Apr 24, 2025 | An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potential... |
| CVE-2025-0639 | HIGH | 7.5 | 0.4% | Apr 24, 2025 | An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro... |
| CVE-2025-41423 | MEDIUM | 4.3 | 0.2% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the ... |
| CVE-2025-41395 | HIGH | 7.5 | 0.4% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th... |
| CVE-2025-3761 | HIGH | 8.8 | 0.3% | Apr 24, 2025 | The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions u... |
| CVE-2025-35965 | HIGH | 7.5 | 0.3% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o... |
| CVE-2025-32730 | MEDIUM | 6.8 | 0.1% | Apr 24, 2025 | Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., ... |
| CVE-2025-2558 | HIGH | 8.6 | 2.1% | Apr 24, 2025 | The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to ... |
| CVE-2025-1453 | MEDIUM | 4.8 | 0.2% | Apr 24, 2025 | The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could ... |
| CVE-2025-3435 | MEDIUM | 4.4 | 0.2% | Apr 24, 2025 | The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote... |
| CVE-2025-46381 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46380 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46379 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46378 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46377 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46376 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46375 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-46374 | — | — | — | Apr 24, 2025 | Rejected reason: Not used |
| CVE-2025-1976 | MEDIUM | 6.7 | 0.7% | Apr 24, 2025 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can ... |
| CVE-2025-46419 | MEDIUM | 5.9 | 0.3% | Apr 24, 2025 | Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet. |
| CVE-2025-46417 | HIGH | 7.5 | 0.2% | Apr 24, 2025 | The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltra... |
| CVE-2025-27581 | MEDIUM | 4.3 | 0.3% | Apr 24, 2025 | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now