2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3766 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil... |
| CVE-2025-4220 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' ... |
| CVE-2025-4055 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s... |
| CVE-2025-4054 | MEDIUM | 6.1 | 0.4% | May 7, 2025 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights fu... |
| CVE-2025-3924 | MEDIUM | 5.3 | 0.3% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public... |
| CVE-2025-3860 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in al... |
| CVE-2025-3853 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.... |
| CVE-2025-3851 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire... |
| CVE-2025-2821 | MEDIUM | 5.3 | 0.3% | May 7, 2025 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-3218 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation ... |
| CVE-2025-47418 | MEDIUM | 5.3 | 0.3% | May 6, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi... |
| CVE-2025-47417 | MEDIUM | 5.1 | 0.4% | May 6, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi... |
| CVE-2025-47256 | MEDIUM | 5.6 | 0.2% | May 6, 2025 | Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha form... |
| CVE-2025-4388 | MEDIUM | 6.1 | 3.4% | May 6, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024... |
| CVE-2025-44900 | MEDIUM | 6.5 | 0.2% | May 6, 2025 | In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the m... |
| CVE-2025-37730 | MEDIUM | 6.5 | 0.1% | May 6, 2025 | Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod... |
| CVE-2025-46736 | MEDIUM | 5.3 | 0.3% | May 6, 2025 | Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal... |
| CVE-2025-45250 | MEDIUM | 5.5 | 0.2% | May 6, 2025 | MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/u... |
| CVE-2025-32022 | MEDIUM | 4.6 | 0.1% | May 6, 2025 | Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot whi... |
| CVE-2025-26262 | MEDIUM | 6.5 | 0.3% | May 6, 2025 | An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate... |
| CVE-2025-4384 | MEDIUM | 6 | 0.1% | May 6, 2025 | The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet becom... |
| CVE-2025-23379 | MEDIUM | 5.2 | 0.2% | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During We... |
| CVE-2025-22479 | MEDIUM | 4.3 | 0.2% | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Res... |
| CVE-2025-4374 | MEDIUM | 6.5 | 0.3% | May 6, 2025 | A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't bee... |
| CVE-2025-4373 | MEDIUM | 4.8 | 0.5% | May 6, 2025 | A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now