2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4194 | MEDIUM | 6.1 | 0.1% | May 17, 2025 | The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-4189 | MEDIUM | 6.1 | 0.1% | May 17, 2025 | The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-4805 | MEDIUM | 4.8 | 0.4% | May 16, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-4804 | MEDIUM | 4.8 | 0.4% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-48188 | MEDIUM | 5.5 | 0.1% | May 16, 2025 | libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib... |
| CVE-2025-32407 | MEDIUM | 5.9 | 0.3% | May 16, 2025 | Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate T... |
| CVE-2025-4476 | MEDIUM | 4.3 | 0.3% | May 16, 2025 | A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered whe... |
| CVE-2025-48146 | MEDIUM | 6.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline lupsonline-link-netwerk allows St... |
| CVE-2025-48144 | MEDIUM | 6.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce al... |
| CVE-2025-48137 | MEDIUM | 6.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview... |
| CVE-2025-48135 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptiva... |
| CVE-2025-48132 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons ... |
| CVE-2025-48131 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra... |
| CVE-2025-48128 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allo... |
| CVE-2025-48127 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app push-notification-mobile-and-w... |
| CVE-2025-48121 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP N... |
| CVE-2025-48120 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vect... |
| CVE-2025-48119 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase rs-wp-books-... |
| CVE-2025-48117 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in kilbot WooCommerce POS woocommerce-pos allows Exploiting Incorrectly Configured A... |
| CVE-2025-48116 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Con... |
| CVE-2025-48115 | MEDIUM | 4.3 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows ... |
| CVE-2025-48113 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broads... |
| CVE-2025-48080 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann... |
| CVE-2025-48079 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Ex... |
| CVE-2025-47564 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now