2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4747 | MEDIUM | 6.3 | 1.2% | May 16, 2025 | A vulnerability was found in Bohua NetDragon Firewall 1.0 and classified as critical. This issue affects some unknown pr... |
| CVE-2025-48175 | MEDIUM | 6.5 | 0.3% | May 16, 2025 | In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes,... |
| CVE-2025-4745 | MEDIUM | 5.4 | 0.3% | May 16, 2025 | A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affect... |
| CVE-2025-4744 | MEDIUM | 4.6 | 0.3% | May 16, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affect... |
| CVE-2025-4742 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9... |
| CVE-2025-4740 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affect... |
| CVE-2025-4169 | MEDIUM | 6.4 | 0.2% | May 16, 2025 | The Posts per Cat [Unmaintained plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppc'... |
| CVE-2025-4729 | MEDIUM | 6.3 | 1.2% | May 16, 2025 | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affecte... |
| CVE-2025-47930 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create p... |
| CVE-2025-4727 | MEDIUM | 6.3 | 0.6% | May 15, 2025 | A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.as... |
| CVE-2025-0921 | MEDIUM | 6.5 | 0.2% | May 15, 2025 | Execution with Unnecessary Privileges vulnerability in multiple services of Mitsubishi Electric GENESIS64 versions 10.97... |
| CVE-2025-4720 | MEDIUM | 5.4 | 0.5% | May 15, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This... |
| CVE-2025-1138 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in f... |
| CVE-2025-47789 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attac... |
| CVE-2025-47786 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that all... |
| CVE-2025-46834 | MEDIUM | 6.6 | 0.3% | May 15, 2025 | Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the ... |
| CVE-2025-2248 | MEDIUM | 5.4 | 0.1% | May 15, 2025 | The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement... |
| CVE-2025-2247 | MEDIUM | 5.4 | 0.1% | May 15, 2025 | The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2025-2203 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statemen... |
| CVE-2025-1454 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2025-1303 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2025-1289 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2025-1288 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2025-1286 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting... |
| CVE-2025-1033 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now