2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48738 | MEDIUM | 6.9 | 0.4% | May 23, 2025 | An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, an... |
| CVE-2025-48735 | MEDIUM | 4.3 | 0.3% | May 23, 2025 | A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230... |
| CVE-2025-46176 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotel... |
| CVE-2025-44998 | MEDIUM | 6.1 | 0.2% | May 23, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows... |
| CVE-2025-48378 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48377 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48375 | MEDIUM | 5.3 | 0.4% | May 23, 2025 | Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equiva... |
| CVE-2025-32967 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. A logging overs... |
| CVE-2025-3580 | MEDIUM | 5.5 | 0.4% | May 23, 2025 | An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently dele... |
| CVE-2025-48275 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-48271 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-47619 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affec... |
| CVE-2025-47529 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Butto... |
| CVE-2025-47513 | MEDIUM | 4.9 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CR... |
| CVE-2025-46527 | MEDIUM | 6.5 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likec... |
| CVE-2025-46518 | MEDIUM | 6.5 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT R... |
| CVE-2025-46493 | MEDIUM | 6.5 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Cr... |
| CVE-2025-46486 | MEDIUM | 4.9 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay ... |
| CVE-2025-41380 | MEDIUM | 6.1 | 0.1% | May 23, 2025 | Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a loca... |
| CVE-2025-41379 | MEDIUM | 6.3 | 0.4% | May 23, 2025 | The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a ... |
| CVE-2025-41378 | MEDIUM | 6.9 | 0.2% | May 23, 2025 | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploi... |
| CVE-2025-3894 | MEDIUM | 4.8 | 0.4% | May 23, 2025 | Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In... |
| CVE-2025-4379 | MEDIUM | 5.1 | 0.4% | May 23, 2025 | DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in s... |
| CVE-2025-5096 | MEDIUM | 5.4 | 0.4% | May 23, 2025 | The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data... |
| CVE-2025-47149 | MEDIUM | 6.9 | 0.1% | May 23, 2025 | The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now