2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4631 | CRITICAL | 9.8 | 0.6% | May 31, 2025 | The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt... |
| CVE-2025-4607 | CRITICAL | 9.8 | 0.5% | May 31, 2025 | The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,... |
| CVE-2025-5370 | CRITICAL | 9.8 | 0.4% | May 31, 2025 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unk... |
| CVE-2025-5369 | CRITICAL | 9.8 | 0.4% | May 31, 2025 | A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected i... |
| CVE-2025-5367 | CRITICAL | 9.8 | 0.4% | May 31, 2025 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulne... |
| CVE-2025-5365 | CRITICAL | 9.8 | 0.4% | May 31, 2025 | A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This a... |
| CVE-2025-5364 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by thi... |
| CVE-2025-5363 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected b... |
| CVE-2025-5362 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte... |
| CVE-2025-5361 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Th... |
| CVE-2025-5360 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability ... |
| CVE-2025-48949 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulner... |
| CVE-2025-5359 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects a... |
| CVE-2025-48938 | CRITICAL | 9.8 | 0.5% | May 30, 2025 | go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been id... |
| CVE-2025-5358 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec... |
| CVE-2025-5357 | CRITICAL | 9.8 | 0.6% | May 30, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability ... |
| CVE-2025-5356 | CRITICAL | 9.8 | 0.6% | May 30, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi... |
| CVE-2025-2500 | CRITICAL | 9.1 | 0.3% | May 30, 2025 | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an... |
| CVE-2025-48865 | CRITICAL | 9.1 | 0.5% | May 30, 2025 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl... |
| CVE-2025-48481 | CRITICAL | 9.8 | 0.5% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated ... |
| CVE-2025-47952 | CRITICAL | 9.1 | 0.8% | May 30, 2025 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a... |
| CVE-2025-48757 | CRITICAL | 9.3 | 0.7% | May 30, 2025 | An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers... |
| CVE-2025-44619 | CRITICAL | 9.1 | 0.3% | May 30, 2025 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attacker... |
| CVE-2025-46352 | CRITICAL | 9.8 | 0.7% | May 30, 2025 | The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string i... |
| CVE-2025-41438 | CRITICAL | 9.8 | 0.7% | May 30, 2025 | The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to ch... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now