2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40626 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr... |
| CVE-2025-47271 | MEDIUM | 6.3 | 0.4% | May 12, 2025 | The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance... |
| CVE-2025-22247 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a... |
| CVE-2025-41393 | MEDIUM | 6.1 | 0.6% | May 12, 2025 | Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implem... |
| CVE-2025-4560 | MEDIUM | 6.9 | 0.3% | May 12, 2025 | The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to a... |
| CVE-2025-3649 | MEDIUM | 6.8 | 0.4% | May 12, 2025 | The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs,... |
| CVE-2025-3597 | MEDIUM | 5.9 | 0.3% | May 12, 2025 | The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executi... |
| CVE-2025-4551 | MEDIUM | 5.4 | 0.3% | May 11, 2025 | A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown fu... |
| CVE-2025-4547 | MEDIUM | 4.8 | 0.3% | May 11, 2025 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl... |
| CVE-2025-4542 | MEDIUM | 4.2 | 0.2% | May 11, 2025 | A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected b... |
| CVE-2025-4536 | MEDIUM | 6.9 | 0.5% | May 11, 2025 | A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classifie... |
| CVE-2025-4535 | MEDIUM | 6.9 | 0.5% | May 11, 2025 | A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Mana... |
| CVE-2025-4534 | MEDIUM | 6.3 | 0.3% | May 11, 2025 | A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some... |
| CVE-2025-4530 | MEDIUM | 5.3 | 0.4% | May 11, 2025 | A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Aff... |
| CVE-2025-4529 | MEDIUM | 5.3 | 0.5% | May 11, 2025 | A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Af... |
| CVE-2025-4527 | MEDIUM | 5.9 | 0.4% | May 11, 2025 | A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function o... |
| CVE-2025-47828 | MEDIUM | 6.4 | 0.2% | May 11, 2025 | Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings. |
| CVE-2025-4526 | MEDIUM | 5.5 | 0.2% | May 11, 2025 | A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the... |
| CVE-2025-4515 | MEDIUM | 6.5 | 0.3% | May 10, 2025 | A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown... |
| CVE-2025-4513 | MEDIUM | 5.3 | 0.4% | May 10, 2025 | A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affec... |
| CVE-2025-4512 | MEDIUM | 5.3 | 0.3% | May 10, 2025 | A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an... |
| CVE-2025-4511 | MEDIUM | 6.3 | 0.4% | May 10, 2025 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue aff... |
| CVE-2025-4510 | MEDIUM | 6.3 | 0.3% | May 10, 2025 | A vulnerability was found in Changjietong UFIDA CRM 1.0. It has been declared as critical. This vulnerability affects un... |
| CVE-2025-3878 | MEDIUM | 5.4 | 0.2% | May 10, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-2944 | MEDIUM | 6.4 | 0.4% | May 10, 2025 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now