2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2890 | MEDIUM | 6.5 | 0.3% | Apr 30, 2025 | The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ ... |
| CVE-2025-3953 | MEDIUM | 5.4 | 0.2% | Apr 30, 2025 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorize... |
| CVE-2025-3471 | MEDIUM | 4.9 | 0.3% | Apr 30, 2025 | The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the... |
| CVE-2025-46552 | MEDIUM | 6.3 | 0.3% | Apr 29, 2025 | KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join yo... |
| CVE-2025-46550 | MEDIUM | 6.1 | 0.5% | Apr 29, 2025 | YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are... |
| CVE-2025-46549 | MEDIUM | 6.1 | 0.5% | Apr 29, 2025 | YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at... |
| CVE-2025-46344 | MEDIUM | 4.9 | 0.4% | Apr 29, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from ... |
| CVE-2025-3910 | MEDIUM | 5.4 | 0.4% | Apr 29, 2025 | A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions... |
| CVE-2025-4078 | MEDIUM | 5.3 | 0.9% | Apr 29, 2025 | A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects s... |
| CVE-2025-4095 | MEDIUM | 4.3 | 0.1% | Apr 29, 2025 | Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers t... |
| CVE-2025-4076 | MEDIUM | 6.3 | 1.9% | Apr 29, 2025 | A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_... |
| CVE-2025-4075 | MEDIUM | 5.3 | 0.3% | Apr 29, 2025 | A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unk... |
| CVE-2025-46350 | MEDIUM | 4.8 | 0.2% | Apr 29, 2025 | YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at... |
| CVE-2025-46349 | MEDIUM | 6.1 | 0.6% | Apr 29, 2025 | YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file uplo... |
| CVE-2025-3911 | MEDIUM | 5.2 | 0.1% | Apr 29, 2025 | Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to ... |
| CVE-2025-0716 | MEDIUM | 4.8 | 0.4% | Apr 29, 2025 | Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allo... |
| CVE-2025-46346 | MEDIUM | 5.4 | 0.3% | Apr 29, 2025 | YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was d... |
| CVE-2025-40616 | MEDIUM | 6.1 | 0.2% | Apr 29, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScrip... |
| CVE-2025-40615 | MEDIUM | 6.1 | 0.2% | Apr 29, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScrip... |
| CVE-2025-23179 | MEDIUM | 5.5 | 0.2% | Apr 29, 2025 | CWE-798: Use of Hard-coded Credentials |
| CVE-2025-1551 | MEDIUM | 6.1 | 0.2% | Apr 29, 2025 | IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This v... |
| CVE-2025-4067 | MEDIUM | 6.9 | 0.4% | Apr 29, 2025 | A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unkno... |
| CVE-2025-4092 | MEDIUM | 6.5 | 0.2% | Apr 29, 2025 | Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-4090 | MEDIUM | 5.3 | 0.3% | Apr 29, 2025 | A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat.... |
| CVE-2025-4089 | MEDIUM | 5.1 | 0.1% | Apr 29, 2025 | Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into us... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now