2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3609 | MEDIUM | 5.3 | 0.2% | May 6, 2025 | The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu... |
| CVE-2025-4305 | MEDIUM | 6.3 | 0.3% | May 6, 2025 | A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the f... |
| CVE-2025-4293 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functiona... |
| CVE-2025-4292 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknow... |
| CVE-2025-1493 | MEDIUM | 5.3 | 0.3% | May 5, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticat... |
| CVE-2025-1000 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 coul... |
| CVE-2025-0915 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 un... |
| CVE-2025-4287 | MEDIUM | 4.8 | 0.1% | May 5, 2025 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi... |
| CVE-2025-4286 | MEDIUM | 4.9 | 0.4% | May 5, 2025 | A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an un... |
| CVE-2025-46734 | MEDIUM | 6.4 | 0.3% | May 5, 2025 | league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of th... |
| CVE-2025-46730 | MEDIUM | 6.5 | 0.4% | May 5, 2025 | MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-... |
| CVE-2025-45618 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all... |
| CVE-2025-46720 | MEDIUM | 4.3 | 0.2% | May 5, 2025 | Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b... |
| CVE-2025-46719 | MEDIUM | 5.4 | 0.4% | May 5, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.... |
| CVE-2025-46571 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.... |
| CVE-2025-46553 | MEDIUM | 6.1 | 0.2% | May 5, 2025 | @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1... |
| CVE-2025-46340 | MEDIUM | 5.4 | 0.2% | May 5, 2025 | Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du... |
| CVE-2025-46335 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo... |
| CVE-2025-29573 | MEDIUM | 6.1 | 0.2% | May 5, 2025 | Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms mo... |
| CVE-2025-4051 | MEDIUM | 6.3 | 0.3% | May 5, 2025 | Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced... |
| CVE-2025-45239 | MEDIUM | 5.3 | 0.7% | May 5, 2025 | An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal. |
| CVE-2025-45236 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to exe... |
| CVE-2025-45240 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php. |
| CVE-2025-43915 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, ... |
| CVE-2025-1992 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now