2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15345 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par... |
| CVE-2025-14870 | HIGH | 7.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-14869 | HIGH | 7.5 | 0.4% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-13874 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-12669 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2025-27853 | HIGH | 7.3 | 0.3% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we... |
| CVE-2025-27852 | MEDIUM | 5 | 0.1% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack... |
| CVE-2025-27851 | CRITICAL | 9.3 | 0.1% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac... |
| CVE-2025-27850 | HIGH | 7.5 | 0.4% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac... |
| CVE-2025-32425 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-29338 | MEDIUM | 5.6 | 0.2% | May 13, 2026 | NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff... |
| CVE-2025-28344 | HIGH | 7.5 | 0.3% | May 13, 2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack. |
| CVE-2025-28343 | HIGH | 7.5 | 0.3% | May 13, 2026 | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons. |
| CVE-2025-14767 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text... |
| CVE-2025-14033 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi... |
| CVE-2025-11159 | HIGH | 7.2 | 0.3% | May 13, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul... |
| CVE-2025-9989 | MEDIUM | 4.4 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-9988 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat... |
| CVE-2025-9987 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2025-14755 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct... |
| CVE-2025-62627 | HIGH | 7.2 | 0.1% | May 13, 2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ... |
| CVE-2025-62624 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-62623 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-61972 | HIGH | 8.5 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma... |
| CVE-2025-61971 | MEDIUM | 5.9 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now