2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48382 | MEDIUM | 5.5 | 0.1% | May 27, 2025 | Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes... |
| CVE-2025-48054 | MEDIUM | 6.8 | 0.6% | May 27, 2025 | Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnera... |
| CVE-2025-4683 | MEDIUM | 4.3 | 0.3% | May 27, 2025 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2025-4682 | MEDIUM | 6.4 | 0.3% | May 27, 2025 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2025-33079 | MEDIUM | 6.5 | 0.3% | May 27, 2025 | IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials ... |
| CVE-2025-4783 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attrib... |
| CVE-2025-46802 | MEDIUM | 6 | 0.2% | May 26, 2025 | For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session. |
| CVE-2025-23392 | MEDIUM | 5.6 | 0.3% | May 26, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows e... |
| CVE-2025-46803 | MEDIUM | 5.1 | 0.2% | May 26, 2025 | The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone t... |
| CVE-2025-37992 | MEDIUM | 5.5 | 0.2% | May 26, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change()... |
| CVE-2025-46805 | MEDIUM | 5.7 | 0.2% | May 26, 2025 | Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to pr... |
| CVE-2025-39498 | MEDIUM | 5.3 | 0.2% | May 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) al... |
| CVE-2025-5185 | MEDIUM | 5.3 | 0.2% | May 26, 2025 | A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as... |
| CVE-2025-40667 | MEDIUM | 6.5 | 0.2% | May 26, 2025 | Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionalit... |
| CVE-2025-40663 | MEDIUM | 5.1 | 0.3% | May 26, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated ... |
| CVE-2025-40653 | MEDIUM | 6.9 | 0.4% | May 26, 2025 | User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a differen... |
| CVE-2025-40652 | MEDIUM | 5.3 | 0.3% | May 26, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in the CoverManager booking software. This allows an attacker to inject ... |
| CVE-2025-5183 | MEDIUM | 4.7 | 0.2% | May 26, 2025 | A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as proble... |
| CVE-2025-5181 | MEDIUM | 4.1 | 0.4% | May 26, 2025 | A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor... |
| CVE-2025-5177 | MEDIUM | 4.7 | 0.5% | May 26, 2025 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This... |
| CVE-2025-4057 | MEDIUM | 5.5 | 0.1% | May 26, 2025 | A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between se... |
| CVE-2025-4053 | MEDIUM | 6.8 | 0.1% | May 26, 2025 | The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel gues... |
| CVE-2025-1985 | MEDIUM | 6.1 | 0.3% | May 26, 2025 | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H... |
| CVE-2025-5175 | MEDIUM | 5.5 | 0.2% | May 26, 2025 | A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the functio... |
| CVE-2025-41441 | MEDIUM | 5.3 | 0.3% | May 26, 2025 | Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unau... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now