2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28200 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits o... |
| CVE-2025-45887 | CRITICAL | 9.1 | 0.4% | May 9, 2025 | Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. |
| CVE-2025-45885 | CRITICAL | 9.8 | 0.4% | May 9, 2025 | PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att... |
| CVE-2025-1087 | CRITICAL | 9.3 | 1.0% | May 9, 2025 | Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to exe... |
| CVE-2025-4403 | CRITICAL | 9.8 | 1.8% | May 9, 2025 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a... |
| CVE-2025-4468 | CRITICAL | 9.8 | 0.9% | May 9, 2025 | A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This iss... |
| CVE-2025-4467 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been declared as critical. This ... |
| CVE-2025-3605 | CRITICAL | 9.8 | 6.4% | May 9, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2025-2253 | CRITICAL | 9.8 | 0.7% | May 9, 2025 | The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and inclu... |
| CVE-2025-4466 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an... |
| CVE-2025-4465 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this issue i... |
| CVE-2025-4464 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this vu... |
| CVE-2025-3463 | CRITICAL | 9.4 | 0.8% | May 9, 2025 | "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici... |
| CVE-2025-4463 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. Affected is an u... |
| CVE-2025-47737 | CRITICAL | 9.8 | 0.5% | May 9, 2025 | lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero. |
| CVE-2025-47735 | CRITICAL | 9.8 | 0.3% | May 9, 2025 | inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization. |
| CVE-2025-4457 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerabilit... |
| CVE-2025-4456 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown f... |
| CVE-2025-3714 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-3711 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-3710 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-4454 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4453 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function form... |
| CVE-2025-3811 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2025-3810 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now