2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4281 | MEDIUM | 5.3 | 0.3% | May 5, 2025 | A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business... |
| CVE-2025-45320 | MEDIUM | 5.3 | 0.3% | May 5, 2025 | A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management... |
| CVE-2025-27921 | MEDIUM | 6.1 | 0.4% | May 5, 2025 | A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized... |
| CVE-2025-26241 | MEDIUM | 6.5 | 0.2% | May 5, 2025 | A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authentica... |
| CVE-2025-25504 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows ... |
| CVE-2025-4316 | MEDIUM | 4.3 | 0.3% | May 5, 2025 | Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even i... |
| CVE-2025-47268 | MEDIUM | 6.5 | 1.3% | May 5, 2025 | ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafte... |
| CVE-2025-45751 | MEDIUM | 6.1 | 0.2% | May 5, 2025 | SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin... |
| CVE-2025-4271 | MEDIUM | 6.9 | 0.5% | May 5, 2025 | A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi... |
| CVE-2025-4269 | MEDIUM | 5.3 | 0.5% | May 5, 2025 | A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown proc... |
| CVE-2025-4268 | MEDIUM | 6.9 | 0.9% | May 5, 2025 | A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unkn... |
| CVE-2025-3583 | MEDIUM | 4.8 | 0.3% | May 5, 2025 | The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2025-39363 | MEDIUM | 5.4 | 0.2% | May 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTea... |
| CVE-2025-4261 | MEDIUM | 5.3 | 0.2% | May 5, 2025 | A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as ... |
| CVE-2025-20670 | MEDIUM | 5.7 | 0.3% | May 5, 2025 | In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote inform... |
| CVE-2025-20665 | MEDIUM | 5.5 | 0.1% | May 5, 2025 | In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local informa... |
| CVE-2025-4257 | MEDIUM | 6.1 | 0.3% | May 5, 2025 | A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown pro... |
| CVE-2025-4256 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file ... |
| CVE-2025-47241 | MEDIUM | 4 | 0.5% | May 3, 2025 | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be pla... |
| CVE-2025-1838 | MEDIUM | 6.5 | 0.3% | May 3, 2025 | IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user ... |
| CVE-2025-1495 | MEDIUM | 4.3 | 0.2% | May 3, 2025 | IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to mis... |
| CVE-2025-37799 | MEDIUM | 5.5 | 0.2% | May 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix malformed packet sizing in vmxnet3_pro... |
| CVE-2025-3815 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up... |
| CVE-2025-4222 | MEDIUM | 5.9 | 0.4% | May 3, 2025 | The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-4199 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now