2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2158 | HIGH | 8.8 | 0.7% | May 10, 2025 | The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L... |
| CVE-2025-4497 | HIGH | 7.8 | 0.3% | May 10, 2025 | A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue af... |
| CVE-2025-1137 | HIGH | 8.8 | 0.3% | May 10, 2025 | IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil... |
| CVE-2025-47424 | HIGH | 7.1 | 0.1% | May 9, 2025 | Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, ... |
| CVE-2025-4447 | HIGH | 7.8 | 0.2% | May 9, 2025 | In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by m... |
| CVE-2025-47269 | HIGH | 8.3 | 34.3% | May 9, 2025 | code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted ... |
| CVE-2025-4480 | HIGH | 7.8 | 0.3% | May 9, 2025 | A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This ... |
| CVE-2025-29509 | HIGH | 8.8 | 0.5% | May 9, 2025 | Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conve... |
| CVE-2025-1278 | HIGH | 7.5 | 0.3% | May 9, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 1... |
| CVE-2025-28203 | HIGH | 8.8 | 1.1% | May 9, 2025 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. |
| CVE-2025-28202 | HIGH | 8.8 | 0.5% | May 9, 2025 | Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services witho... |
| CVE-2025-4206 | HIGH | 7.2 | 1.3% | May 9, 2025 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner... |
| CVE-2025-3528 | HIGH | 8.2 | 0.2% | May 9, 2025 | A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has... |
| CVE-2025-4472 | HIGH | 7.8 | 0.4% | May 9, 2025 | A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical.... |
| CVE-2025-4471 | HIGH | 7.8 | 0.3% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0.... |
| CVE-2025-3455 | HIGH | 8.8 | 1.2% | May 9, 2025 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized... |
| CVE-2025-37885 | HIGH | 7.8 | 0.3% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route... |
| CVE-2025-37882 | HIGH | 7.8 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun ev... |
| CVE-2025-37879 | HIGH | 7.1 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative rea... |
| CVE-2025-37869 | HIGH | 7.8 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Use local fence in error path of xe_migrate... |
| CVE-2025-37861 | HIGH | 7.8 | 0.3% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Synchronous access b/w reset and tm t... |
| CVE-2025-37854 | HIGH | 7.8 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix mode1 reset crash issue If HW sche... |
| CVE-2025-37849 | HIGH | 7.8 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation ... |
| CVE-2025-37846 | HIGH | 7.1 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: mops: Do not dereference src reg for a set o... |
| CVE-2025-37845 | HIGH | 7.8 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now