2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3479 | MEDIUM | 5.3 | 0.2% | Apr 17, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Repl... |
| CVE-2025-3453 | MEDIUM | 5.3 | 0.3% | Apr 17, 2025 | The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect... |
| CVE-2025-26478 | MEDIUM | 6.5 | 0.1% | Apr 17, 2025 | Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker... |
| CVE-2025-26477 | HIGH | 8.8 | 0.3% | Apr 17, 2025 | Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with re... |
| CVE-2025-29931 | MEDIUM | 6.3 | 0.4% | Apr 17, 2025 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not... |
| CVE-2025-2197 | MEDIUM | 4.3 | 0.2% | Apr 17, 2025 | Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service av... |
| CVE-2025-2188 | CRITICAL | 9.1 | 0.3% | Apr 17, 2025 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co... |
| CVE-2025-1532 | CRITICAL | 9.1 | 0.3% | Apr 17, 2025 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affec... |
| CVE-2025-3615 | MEDIUM | 6.4 | 0.3% | Apr 17, 2025 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in ... |
| CVE-2025-3113 | CRITICAL | 9 | 0.3% | Apr 17, 2025 | A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database con... |
| CVE-2025-2903 | HIGH | 8.5 | 0.2% | Apr 17, 2025 | An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Lo... |
| CVE-2025-3295 | MEDIUM | 4.9 | 0.4% | Apr 17, 2025 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T... |
| CVE-2025-3294 | HIGH | 7.2 | 0.8% | Apr 17, 2025 | The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all ver... |
| CVE-2025-1525 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-1524 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-1523 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-43717 | MEDIUM | 5.4 | 0.3% | Apr 17, 2025 | In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and ... |
| CVE-2025-43715 | HIGH | 8.1 | 0.2% | Apr 17, 2025 | Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM dur... |
| CVE-2025-31340 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Informa... |
| CVE-2025-31339 | MEDIUM | 5.3 | 0.4% | Apr 17, 2025 | An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro ... |
| CVE-2025-31338 | MEDIUM | 6.9 | 0.4% | Apr 17, 2025 | A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 thr... |
| CVE-2025-43708 | HIGH | 7.5 | 0.3% | Apr 17, 2025 | VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMa... |
| CVE-2025-1290 | HIGH | 8.1 | 0.3% | Apr 17, 2025 | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4... |
| CVE-2025-43704 | MEDIUM | 4.7 | 0.1% | Apr 16, 2025 | Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authenticatio... |
| CVE-2025-2400 | — | — | — | Apr 16, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now