2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39517 | MEDIUM | 4.3 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Basic Interactive World Map basic-interactive-world-ma... |
| CVE-2025-39516 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alan Petersen Auth... |
| CVE-2025-39515 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tnomi Attendance M... |
| CVE-2025-39514 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Fo... |
| CVE-2025-39513 | MEDIUM | 5.3 | 0.5% | Apr 16, 2025 | Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND activedemand allows ... |
| CVE-2025-39512 | MEDIUM | 4.3 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor bulk-term-editor allows Cross Site Requ... |
| CVE-2025-1983 | MEDIUM | 5.1 | 0.5% | Apr 16, 2025 | A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary ... |
| CVE-2025-3688 | MEDIUM | 4.8 | 0.3% | Apr 16, 2025 | A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects a... |
| CVE-2025-3687 | MEDIUM | 5.3 | 0.2% | Apr 16, 2025 | A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. Affected by this issue is s... |
| CVE-2025-3686 | MEDIUM | 5.3 | 0.5% | Apr 16, 2025 | A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the functi... |
| CVE-2025-22021 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT ... |
| CVE-2025-22019 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch... |
| CVE-2025-31363 | MEDIUM | 6.5 | 0.2% | Apr 16, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to... |
| CVE-2025-27936 | MEDIUM | 5.9 | 0.3% | Apr 16, 2025 | Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enable... |
| CVE-2025-3677 | MEDIUM | 5.3 | 0.2% | Apr 16, 2025 | A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the functio... |
| CVE-2025-3104 | MEDIUM | 5.3 | 0.3% | Apr 16, 2025 | The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and... |
| CVE-2025-3077 | MEDIUM | 5.4 | 0.2% | Apr 16, 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custo... |
| CVE-2025-27571 | MEDIUM | 4.3 | 0.2% | Apr 16, 2025 | Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived... |
| CVE-2025-24839 | MEDIUM | 4.3 | 0.2% | Apr 16, 2025 | Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering ... |
| CVE-2025-0101 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time li... |
| CVE-2025-3675 | MEDIUM | 5.3 | 0.5% | Apr 16, 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issu... |
| CVE-2025-3674 | MEDIUM | 6.9 | 0.5% | Apr 16, 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this v... |
| CVE-2025-3247 | MEDIUM | 5.3 | 0.2% | Apr 16, 2025 | The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via th... |
| CVE-2025-3668 | MEDIUM | 6.9 | 1.1% | Apr 16, 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability... |
| CVE-2025-3667 | MEDIUM | 6.9 | 0.5% | Apr 16, 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now