2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1627 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them ... |
| CVE-2025-1626 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before output... |
| CVE-2025-1625 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputti... |
| CVE-2025-2892 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-23167 | MEDIUM | 6.5 | 0.5% | May 19, 2025 | A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required... |
| CVE-2025-23164 | MEDIUM | 4.4 | 0.3% | May 19, 2025 | A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the re... |
| CVE-2025-4904 | MEDIUM | 5.3 | 1.0% | May 19, 2025 | A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. This vulnerabilit... |
| CVE-2025-4901 | MEDIUM | 6.5 | 66.1% | May 19, 2025 | A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerabi... |
| CVE-2025-4898 | MEDIUM | 5.4 | 0.5% | May 18, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This... |
| CVE-2025-4894 | MEDIUM | 5.9 | 0.2% | May 18, 2025 | A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391... |
| CVE-2025-4893 | MEDIUM | 6.3 | 0.4% | May 18, 2025 | A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d... |
| CVE-2025-4868 | MEDIUM | 6.3 | 0.4% | May 18, 2025 | A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has b... |
| CVE-2025-4862 | MEDIUM | 6.1 | 0.4% | May 18, 2025 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affe... |
| CVE-2025-3715 | MEDIUM | 6.4 | 0.2% | May 18, 2025 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in a... |
| CVE-2025-4860 | MEDIUM | 4.8 | 0.6% | May 18, 2025 | A vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137_ALL_en_20210528. Affected is an u... |
| CVE-2025-4859 | MEDIUM | 4.8 | 0.7% | May 18, 2025 | A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue af... |
| CVE-2025-4858 | MEDIUM | 4.8 | 0.6% | May 18, 2025 | A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been declared as problematic. This vulne... |
| CVE-2025-4850 | MEDIUM | 6.3 | 1.2% | May 18, 2025 | A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function ... |
| CVE-2025-4838 | MEDIUM | 5.3 | 0.3% | May 17, 2025 | A vulnerability, which was classified as problematic, was found in kanwangzjm Funiture up to 71ca0fb0658b3d839d9e049ac36... |
| CVE-2025-47931 | MEDIUM | 6.1 | 0.3% | May 17, 2025 | LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Sit... |
| CVE-2025-4101 | MEDIUM | 4.3 | 0.2% | May 17, 2025 | The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss... |
| CVE-2025-4669 | MEDIUM | 5.4 | 0.3% | May 17, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod... |
| CVE-2025-3888 | MEDIUM | 5.4 | 0.3% | May 17, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi... |
| CVE-2025-3527 | MEDIUM | 5.4 | 0.2% | May 17, 2025 | The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2025-4610 | MEDIUM | 6.4 | 0.3% | May 17, 2025 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now