2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5054 | MEDIUM | 4.7 | 0.3% | May 30, 2025 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via ... |
| CVE-2025-48887 | MEDIUM | 6.5 | 0.4% | May 30, 2025 | vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDo... |
| CVE-2025-3611 | MEDIUM | 4.3 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restr... |
| CVE-2025-3230 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate... |
| CVE-2025-2571 | MEDIUM | 4.2 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c... |
| CVE-2025-4598 | MEDIUM | 4.7 | 0.8% | May 30, 2025 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace... |
| CVE-2025-40909 | MEDIUM | 5.9 | 0.4% | May 30, 2025 | Perl threads have a working directory race condition where file operations may target unintended paths. If a directory ... |
| CVE-2025-1484 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite... |
| CVE-2025-4944 | MEDIUM | 6.4 | 0.2% | May 30, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-4597 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-5235 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ paramete... |
| CVE-2025-5142 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-4635 | MEDIUM | 6.6 | 0.3% | May 30, 2025 | A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to ... |
| CVE-2025-4634 | MEDIUM | 4.1 | 0.2% | May 30, 2025 | The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privile... |
| CVE-2025-4633 | MEDIUM | 6.5 | 0.2% | May 30, 2025 | Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor... |
| CVE-2025-48912 | MEDIUM | 6.5 | 0.6% | May 30, 2025 | An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injec... |
| CVE-2025-48334 | MEDIUM | 4.3 | 0.2% | May 30, 2025 | Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocom... |
| CVE-2025-5236 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ par... |
| CVE-2025-4431 | MEDIUM | 4.3 | 0.3% | May 30, 2025 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2025-4943 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-... |
| CVE-2025-48880 | MEDIUM | 6.6 | 0.3% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account i... |
| CVE-2025-48875 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validatio... |
| CVE-2025-48489 | MEDIUM | 4.8 | 0.2% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to... |
| CVE-2025-48488 | MEDIUM | 5.4 | 0.2% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allo... |
| CVE-2025-48487 | MEDIUM | 4.8 | 0.2% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now