2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48882 | HIGH | 8.7 | 0.4% | May 30, 2025 | PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to versio... |
| CVE-2025-2503 | HIGH | 7.1 | 0.1% | May 30, 2025 | An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to per... |
| CVE-2025-2502 | HIGH | 8.5 | 0.2% | May 30, 2025 | An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to ele... |
| CVE-2025-2501 | HIGH | 8.5 | 0.2% | May 30, 2025 | An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate pr... |
| CVE-2025-4992 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Re... |
| CVE-2025-4991 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3... |
| CVE-2025-4990 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIEN... |
| CVE-2025-4989 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2... |
| CVE-2025-4988 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer... |
| CVE-2025-4986 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENC... |
| CVE-2025-4985 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3D... |
| CVE-2025-4984 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPER... |
| CVE-2025-4983 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DE... |
| CVE-2025-0602 | HIGH | 8.7 | 0.3% | May 30, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DE... |
| CVE-2025-48331 | HIGH | 7.5 | 0.3% | May 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter wooc... |
| CVE-2025-4433 | HIGH | 8.8 | 0.5% | May 30, 2025 | Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrativ... |
| CVE-2025-5190 | HIGH | 8.8 | 0.4% | May 30, 2025 | The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is... |
| CVE-2025-1763 | HIGH | 8.7 | 0.5% | May 30, 2025 | An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass... |
| CVE-2025-4636 | HIGH | 7.8 | 0.1% | May 30, 2025 | Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co... |
| CVE-2025-48936 | HIGH | 8.8 | 0.4% | May 30, 2025 | Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln... |
| CVE-2025-48492 | HIGH | 8.8 | 0.8% | May 30, 2025 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with acc... |
| CVE-2025-47697 | HIGH | 7.5 | 0.3% | May 30, 2025 | Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated a... |
| CVE-2025-41385 | HIGH | 7.2 | 1.2% | May 30, 2025 | An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman... |
| CVE-2025-48889 | HIGH | 7.5 | 0.6% | May 30, 2025 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod... |
| CVE-2025-48881 | HIGH | 8.3 | 0.3% | May 30, 2025 | Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now