2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4258 | HIGH | 8.8 | 0.3% | May 5, 2025 | A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the func... |
| CVE-2025-4247 | HIGH | 8.8 | 0.4% | May 4, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is... |
| CVE-2025-47245 | HIGH | 8.1 | 0.4% | May 4, 2025 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. |
| CVE-2025-47244 | HIGH | 7.3 | 0.4% | May 3, 2025 | Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, ... |
| CVE-2025-4244 | HIGH | 8.8 | 0.4% | May 3, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This af... |
| CVE-2025-4243 | HIGH | 8.8 | 0.4% | May 3, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Af... |
| CVE-2025-46723 | HIGH | 7.8 | 0.4% | May 2, 2025 | OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is... |
| CVE-2025-4218 | HIGH | 7.8 | 0.3% | May 2, 2025 | A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulne... |
| CVE-2025-3879 | HIGH | 8.8 | 0.4% | May 2, 2025 | Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued ... |
| CVE-2025-4210 | HIGH | 7.3 | 1.8% | May 2, 2025 | A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function Handl... |
| CVE-2025-37798 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_r... |
| CVE-2025-37797 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class h... |
| CVE-2025-1884 | HIGH | 7.8 | 0.2% | May 2, 2025 | Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D... |
| CVE-2025-1883 | HIGH | 7.8 | 0.2% | May 2, 2025 | Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS... |
| CVE-2025-4204 | HIGH | 7.5 | 0.3% | May 2, 2025 | The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versi... |
| CVE-2025-2605 | HIGH | 8.8 | 9.4% | May 2, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB... |
| CVE-2025-0427 | HIGH | 7.8 | 0.1% | May 2, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2025-0072 | HIGH | 7.8 | 0.3% | May 2, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-3438 | HIGH | 7.3 | 0.3% | May 2, 2025 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege e... |
| CVE-2025-4179 | HIGH | 7.3 | 0.3% | May 2, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o... |
| CVE-2025-4197 | HIGH | 8.8 | 0.4% | May 2, 2025 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is... |
| CVE-2025-4196 | HIGH | 8.8 | 0.4% | May 2, 2025 | A vulnerability was found in SourceCodester Patient Record Management System 1.0. It has been rated as critical. This is... |
| CVE-2025-46635 | HIGH | 7.1 | 0.3% | May 1, 2025 | An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network... |
| CVE-2025-46634 | HIGH | 8.2 | 0.1% | May 1, 2025 | Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow ... |
| CVE-2025-46633 | HIGH | 8.2 | 0.2% | May 1, 2025 | Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now