2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4823 | HIGH | 8.8 | 0.7% | May 17, 2025 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Aff... |
| CVE-2025-4190 | HIGH | 7.2 | 0.5% | May 17, 2025 | The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege us... |
| CVE-2025-3812 | HIGH | 8.1 | 0.5% | May 17, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-1706 | HIGH | 7.5 | 0.4% | May 17, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern... |
| CVE-2025-4810 | HIGH | 8.8 | 0.8% | May 16, 2025 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is ... |
| CVE-2025-4809 | HIGH | 8.8 | 1.0% | May 16, 2025 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSaf... |
| CVE-2025-4808 | HIGH | 8.8 | 0.5% | May 16, 2025 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affe... |
| CVE-2025-4807 | HIGH | 7.5 | 0.9% | May 16, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. T... |
| CVE-2025-4802 | HIGH | 7.8 | 0.4% | May 16, 2025 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker c... |
| CVE-2025-4806 | HIGH | 8.8 | 0.4% | May 16, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.... |
| CVE-2025-4795 | HIGH | 7.2 | 0.4% | May 16, 2025 | A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo... |
| CVE-2025-4787 | HIGH | 8.8 | 0.4% | May 16, 2025 | A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected ... |
| CVE-2025-4786 | HIGH | 8.8 | 0.4% | May 16, 2025 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This i... |
| CVE-2025-48138 | HIGH | 8.8 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ... |
| CVE-2025-48136 | HIGH | 8.8 | 0.4% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48134 | HIGH | 7.2 | 0.4% | May 16, 2025 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.... |
| CVE-2025-48114 | HIGH | 7.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fo... |
| CVE-2025-48112 | HIGH | 7.1 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht... |
| CVE-2025-47693 | HIGH | 7.5 | 0.5% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47567 | HIGH | 7.6 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video... |
| CVE-2025-39537 | HIGH | 7.1 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Bet... |
| CVE-2025-39507 | HIGH | 8.8 | 0.7% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39493 | HIGH | 8.8 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-39492 | HIGH | 7.5 | 0.4% | May 16, 2025 | Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 ... |
| CVE-2025-39491 | HIGH | 8.1 | 0.4% | May 16, 2025 | Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through r... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now