2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0993 | MEDIUM | 6.5 | 0.5% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor... |
| CVE-2025-0679 | MEDIUM | 4.3 | 0.3% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2025-0605 | MEDIUM | 4.3 | 0.3% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2025-4575 | MEDIUM | 6.5 | 0.3% | May 22, 2025 | Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use f... |
| CVE-2025-3111 | MEDIUM | 6.5 | 0.4% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2025-2853 | MEDIUM | 6.5 | 0.4% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor... |
| CVE-2025-1110 | MEDIUM | 4.3 | 0.3% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a... |
| CVE-2025-3939 | MEDIUM | 5.3 | 0.3% | May 22, 2025 | Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enter... |
| CVE-2025-3444 | MEDIUM | 6.5 | 1.2% | May 22, 2025 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated L... |
| CVE-2025-4419 | MEDIUM | 4.3 | 0.4% | May 22, 2025 | The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 vi... |
| CVE-2025-4405 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all v... |
| CVE-2025-4280 | MEDIUM | 4.8 | 0.1% | May 22, 2025 | MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissi... |
| CVE-2025-4123 | MEDIUM | 6.1 | 94.4% | May 22, 2025 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire... |
| CVE-2025-4133 | MEDIUM | 5.4 | 0.3% | May 22, 2025 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts whe... |
| CVE-2025-5062 | MEDIUM | 6.1 | 0.4% | May 22, 2025 | The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p... |
| CVE-2025-3885 | MEDIUM | 6.5 | 0.2% | May 22, 2025 | Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows netwo... |
| CVE-2025-3480 | MEDIUM | 6.5 | 0.1% | May 22, 2025 | MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability... |
| CVE-2025-48070 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer tha... |
| CVE-2025-47942 | MEDIUM | 5.3 | 0.4% | May 21, 2025 | The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxap... |
| CVE-2025-45755 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the S... |
| CVE-2025-5033 | MEDIUM | 5.3 | 0.2% | May 21, 2025 | A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unk... |
| CVE-2025-5020 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website... |
| CVE-2025-48069 | MEDIUM | 6.6 | 1.3% | May 21, 2025 | ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `e... |
| CVE-2025-2102 | MEDIUM | 5.7 | 0.1% | May 21, 2025 | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Priv... |
| CVE-2025-4415 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now