2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5405 | MEDIUM | 5.4 | 0.3% | Jun 1, 2025 | A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b5... |
| CVE-2025-33004 | MEDIUM | 6.5 | 0.4% | Jun 1, 2025 | IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper ... |
| CVE-2025-2896 | MEDIUM | 5.4 | 0.2% | Jun 1, 2025 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat... |
| CVE-2025-25044 | MEDIUM | 5.4 | 0.2% | Jun 1, 2025 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat... |
| CVE-2025-1499 | MEDIUM | 6.5 | 0.2% | Jun 1, 2025 | IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext paramete... |
| CVE-2025-5383 | MEDIUM | 4.8 | 0.2% | May 31, 2025 | A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknow... |
| CVE-2025-5380 | MEDIUM | 6.3 | 0.3% | May 31, 2025 | A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ad... |
| CVE-2025-5379 | MEDIUM | 5.3 | 0.2% | May 31, 2025 | A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects... |
| CVE-2025-5378 | MEDIUM | 6.1 | 0.3% | May 31, 2025 | A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown ... |
| CVE-2025-5377 | MEDIUM | 6.1 | 0.3% | May 31, 2025 | A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu... |
| CVE-2025-4691 | MEDIUM | 5.3 | 0.3% | May 31, 2025 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to I... |
| CVE-2025-5290 | MEDIUM | 6.4 | 0.2% | May 31, 2025 | The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-3813 | MEDIUM | 5.4 | 0.2% | May 31, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_ele... |
| CVE-2025-5292 | MEDIUM | 6.4 | 0.2% | May 31, 2025 | The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Buil... |
| CVE-2025-5285 | MEDIUM | 6.4 | 0.2% | May 31, 2025 | The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’... |
| CVE-2025-4595 | MEDIUM | 6.4 | 0.2% | May 31, 2025 | The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fast... |
| CVE-2025-4590 | MEDIUM | 6.4 | 0.2% | May 31, 2025 | The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisy... |
| CVE-2025-5016 | MEDIUM | 4.7 | 0.2% | May 31, 2025 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highl... |
| CVE-2025-48948 | MEDIUM | 6.5 | 0.4% | May 30, 2025 | Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions p... |
| CVE-2025-1479 | MEDIUM | 5.3 | 0.1% | May 30, 2025 | An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a ... |
| CVE-2025-48944 | MEDIUM | 6.5 | 0.4% | May 30, 2025 | vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th... |
| CVE-2025-48943 | MEDIUM | 6.5 | 0.4% | May 30, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a... |
| CVE-2025-48942 | MEDIUM | 6.5 | 0.5% | May 30, 2025 | vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h... |
| CVE-2025-48885 | MEDIUM | 5.7 | 0.2% | May 30, 2025 | application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with vie... |
| CVE-2025-48883 | MEDIUM | 5.3 | 0.4% | May 30, 2025 | Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Se... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now