2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0688 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ... |
| CVE-2025-0687 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ... |
| CVE-2025-0329 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou... |
| CVE-2025-44110 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php. |
| CVE-2025-43853 | MEDIUM | 5.5 | 0.2% | May 15, 2025 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA... |
| CVE-2025-1647 | MEDIUM | 5.6 | 0.3% | May 15, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap a... |
| CVE-2025-48051 | MEDIUM | 6.1 | 0.4% | May 15, 2025 | powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern i... |
| CVE-2025-3440 | MEDIUM | 5.5 | 0.2% | May 15, 2025 | IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to ... |
| CVE-2025-2527 | MEDIUM | 4.3 | 0.3% | May 15, 2025 | Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing gr... |
| CVE-2025-4701 | MEDIUM | 5.3 | 0.2% | May 15, 2025 | A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue... |
| CVE-2025-46053 | MEDIUM | 5.1 | 0.2% | May 15, 2025 | A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive... |
| CVE-2025-44185 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_... |
| CVE-2025-4516 | MEDIUM | 5.9 | 0.2% | May 15, 2025 | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using t... |
| CVE-2025-44183 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via t... |
| CVE-2025-44182 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modeln... |
| CVE-2025-44181 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via... |
| CVE-2025-44180 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={bra... |
| CVE-2025-3446 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct pe... |
| CVE-2025-31947 | MEDIUM | 5.3 | 0.3% | May 15, 2025 | Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users f... |
| CVE-2025-32738 | MEDIUM | 6.9 | 0.4% | May 15, 2025 | Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware... |
| CVE-2025-4737 | MEDIUM | 6.2 | 0.1% | May 15, 2025 | Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of... |
| CVE-2025-27524 | MEDIUM | 5.3 | 0.1% | May 15, 2025 | Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affect... |
| CVE-2025-48027 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolutio... |
| CVE-2025-3742 | MEDIUM | 6.8 | 0.5% | May 15, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes befo... |
| CVE-2025-48024 | MEDIUM | 5 | 0.3% | May 15, 2025 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now