2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39398 | MEDIUM | 4.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Themovation Bellevue bellevuex.This issue affects Bellevue: from n/a through <= 4... |
| CVE-2025-22287 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-fr... |
| CVE-2025-47583 | MEDIUM | 5.4 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross... |
| CVE-2025-46543 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CharlyLeetham Enha... |
| CVE-2025-46263 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lloyd Saunders Aut... |
| CVE-2025-46262 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Mad Mimi... |
| CVE-2025-39394 | MEDIUM | 5.3 | 0.3% | May 19, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP al... |
| CVE-2025-39388 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Solid Plugins AnalyticsWP allows Accessing Functionality Not Properly Constrained... |
| CVE-2025-39376 | MEDIUM | 4.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress car-park-booking-system-for-wo... |
| CVE-2025-39375 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cros... |
| CVE-2025-39373 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2025-39371 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-... |
| CVE-2025-39369 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sihibbs Posts for ... |
| CVE-2025-39368 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-39353 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu... |
| CVE-2025-39351 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request... |
| CVE-2025-26920 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured A... |
| CVE-2025-26867 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.Th... |
| CVE-2025-4939 | MEDIUM | 6.1 | 0.4% | May 19, 2025 | A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vu... |
| CVE-2025-4876 | MEDIUM | 4.4 | 0.1% | May 19, 2025 | ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES... |
| CVE-2025-32920 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders T... |
| CVE-2025-31262 | MEDIUM | 5.5 | 0.1% | May 19, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S... |
| CVE-2025-26621 | MEDIUM | 6.8 | 0.4% | May 19, 2025 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-24184 | MEDIUM | 5.5 | 0.2% | May 19, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, m... |
| CVE-2025-24183 | MEDIUM | 5.5 | 0.1% | May 19, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now