2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48417 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | The certificate and private key used for providing transport layer security for connections to the web interface (TCP po... |
| CVE-2025-48415 | MEDIUM | 6.2 | 0.2% | May 21, 2025 | A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The ... |
| CVE-2025-1418 | MEDIUM | 5.1 | 0.2% | May 21, 2025 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which cont... |
| CVE-2025-1417 | MEDIUM | 4.6 | 0.2% | May 21, 2025 | In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by... |
| CVE-2025-4611 | MEDIUM | 6.4 | 0.5% | May 21, 2025 | The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-4221 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader... |
| CVE-2025-4219 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all v... |
| CVE-2025-4217 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_yo... |
| CVE-2025-4105 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on ... |
| CVE-2025-48414 | MEDIUM | 6.5 | 0.3% | May 21, 2025 | There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts ... |
| CVE-2025-3781 | MEDIUM | 6.4 | 0.3% | May 21, 2025 | The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_don... |
| CVE-2025-3750 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ param... |
| CVE-2025-27804 | MEDIUM | 6.5 | 1.0% | May 21, 2025 | Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishi... |
| CVE-2025-27803 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network ac... |
| CVE-2025-1415 | MEDIUM | 5.1 | 0.2% | May 21, 2025 | A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Dev... |
| CVE-2025-4949 | MEDIUM | 5.3 | 1.1% | May 21, 2025 | In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the Amazo... |
| CVE-2025-5013 | MEDIUM | 4.7 | 0.6% | May 21, 2025 | A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown par... |
| CVE-2025-4969 | MEDIUM | 6.5 | 0.7% | May 21, 2025 | A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination o... |
| CVE-2025-5011 | MEDIUM | 4.7 | 0.4% | May 21, 2025 | A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown co... |
| CVE-2025-5010 | MEDIUM | 4.7 | 0.4% | May 21, 2025 | A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of ... |
| CVE-2025-5007 | MEDIUM | 5.1 | 0.3% | May 20, 2025 | A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability i... |
| CVE-2025-5001 | MEDIUM | 5.5 | 0.2% | May 20, 2025 | A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. Thi... |
| CVE-2025-48056 | MEDIUM | 5.3 | 0.2% | May 20, 2025 | Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to versio... |
| CVE-2025-4996 | MEDIUM | 4.8 | 0.3% | May 20, 2025 | A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some... |
| CVE-2025-47290 | MEDIUM | 5.9 | 0.4% | May 20, 2025 | containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now