2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45611 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via ... |
| CVE-2025-45607 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request. |
| CVE-2025-1909 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,... |
| CVE-2025-4318 | CRITICAL | 9 | 1.0% | May 5, 2025 | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input valida... |
| CVE-2025-4283 | CRITICAL | 9.8 | 0.5% | May 5, 2025 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue... |
| CVE-2025-43852 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43851 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43850 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43849 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-4052 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced... |
| CVE-2025-45238 | CRITICAL | 9.1 | 0.6% | May 5, 2025 | foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method. |
| CVE-2025-43848 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43847 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43846 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43845 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43844 | CRITICAL | 9.8 | 2.1% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43843 | CRITICAL | 9.8 | 2.3% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43842 | CRITICAL | 9.8 | 2.1% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-24977 | CRITICAL | 9.1 | 0.8% | May 5, 2025 | OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manag... |
| CVE-2025-45042 | CRITICAL | 9.8 | 1.8% | May 5, 2025 | Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function. |
| CVE-2025-28168 | CRITICAL | 9.8 | 0.3% | May 5, 2025 | The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs be... |
| CVE-2025-2905 | CRITICAL | 9.1 | 1.1% | May 5, 2025 | Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, e... |
| CVE-2025-4266 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by thi... |
| CVE-2025-4265 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this v... |
| CVE-2025-4264 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now