2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4591 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcod... |
| CVE-2025-4589 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in... |
| CVE-2025-4126 | MEDIUM | 6.4 | 0.2% | May 15, 2025 | The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a... |
| CVE-2025-47783 | MEDIUM | 6.1 | 0.5% | May 14, 2025 | Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an at... |
| CVE-2025-46836 | MEDIUM | 6.6 | 0.2% | May 14, 2025 | net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operatin... |
| CVE-2025-29691 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29690 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29689 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29688 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-29686 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr... |
| CVE-2025-47888 | MEDIUM | 5.9 | 0.2% | May 14, 2025 | Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne... |
| CVE-2025-47887 | MEDIUM | 4.3 | 0.3% | May 14, 2025 | Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers wit... |
| CVE-2025-47886 | MEDIUM | 4.3 | 0.2% | May 14, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earl... |
| CVE-2025-44024 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exist... |
| CVE-2025-25370 | MEDIUM | 4.6 | 0.2% | May 14, 2025 | An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain... |
| CVE-2025-0137 | MEDIUM | 4.8 | 0.3% | May 14, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
| CVE-2025-0136 | MEDIUM | 5.3 | 0.1% | May 14, 2025 | Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, P... |
| CVE-2025-0134 | MEDIUM | 6.5 | 0.4% | May 14, 2025 | A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute a... |
| CVE-2025-0132 | MEDIUM | 6.9 | 0.4% | May 14, 2025 | A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to dis... |
| CVE-2025-4664 | MEDIUM | 4.3 | 5.3% | May 14, 2025 | Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro... |
| CVE-2025-46786 | MEDIUM | 6.1 | 0.3% | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc... |
| CVE-2025-46785 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service ... |
| CVE-2025-30668 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network... |
| CVE-2025-30667 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-30666 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now