2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4300 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unkn... |
| CVE-2025-4299 | CRITICAL | 9.8 | 0.7% | May 6, 2025 | A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the funct... |
| CVE-2025-4298 | CRITICAL | 9.8 | 0.9% | May 6, 2025 | A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affect... |
| CVE-2025-4297 | CRITICAL | 9.8 | 0.5% | May 5, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affect... |
| CVE-2025-4291 | CRITICAL | 9.8 | 0.3% | May 5, 2025 | A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. ... |
| CVE-2025-4290 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk... |
| CVE-2025-44074 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php. |
| CVE-2025-44072 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php. |
| CVE-2025-44071 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This ... |
| CVE-2025-4289 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t... |
| CVE-2025-4288 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com... |
| CVE-2025-46726 | CRITICAL | 9.1 | 0.5% | May 5, 2025 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM applicati... |
| CVE-2025-45616 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a craft... |
| CVE-2025-45615 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights... |
| CVE-2025-45612 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. |
| CVE-2025-45611 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via ... |
| CVE-2025-45607 | CRITICAL | 9.8 | 0.4% | May 5, 2025 | An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request. |
| CVE-2025-1909 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,... |
| CVE-2025-4318 | CRITICAL | 9 | 1.0% | May 5, 2025 | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input valida... |
| CVE-2025-4283 | CRITICAL | 9.8 | 0.5% | May 5, 2025 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue... |
| CVE-2025-43852 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43851 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43850 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43849 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-4052 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now