2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47540 | HIGH | 7.5 | 0.3% | May 7, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows ... |
| CVE-2025-47538 | HIGH | 7.2 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart track... |
| CVE-2025-47537 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF In... |
| CVE-2025-47533 | HIGH | 8.1 | 0.3% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PH... |
| CVE-2025-47531 | HIGH | 8.8 | 0.5% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47514 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget spostarbust allows St... |
| CVE-2025-47510 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47508 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47498 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47496 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47494 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47491 | HIGH | 7.4 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Si... |
| CVE-2025-47490 | HIGH | 8.5 | 0.3% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimat... |
| CVE-2025-47462 | HIGH | 8.8 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privil... |
| CVE-2025-47460 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TrackShip TrackShi... |
| CVE-2025-47440 | HIGH | 7.5 | 0.6% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47439 | HIGH | 7.5 | 0.7% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-2775 | HIGH | 7.5 | 55.2% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the C... |
| CVE-2025-29448 | HIGH | 7.5 | 0.5% | May 7, 2025 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively ... |
| CVE-2025-29152 | HIGH | 7.6 | 0.3% | May 7, 2025 | Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary co... |
| CVE-2025-33093 | HIGH | 7.5 | 0.3% | May 7, 2025 | IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored... |
| CVE-2025-27533 | HIGH | 7.5 | 8.6% | May 7, 2025 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands... |
| CVE-2025-20979 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code. |
| CVE-2025-20976 | HIGH | 7.5 | 0.2% | May 7, 2025 | Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to re... |
| CVE-2025-20964 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to wri... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now