2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2797 | MEDIUM | 5.4 | 0.1% | Apr 4, 2025 | The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-3214 | MEDIUM | 5.3 | 0.4% | Apr 4, 2025 | A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability i... |
| CVE-2025-2836 | MEDIUM | 6.4 | 0.3% | Apr 4, 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-2279 | MEDIUM | 5.9 | 0.2% | Apr 4, 2025 | The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting... |
| CVE-2025-2159 | MEDIUM | 5.1 | 0.2% | Apr 4, 2025 | Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local ... |
| CVE-2025-3191 | MEDIUM | 6.1 | 0.2% | Apr 4, 2025 | All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button whi... |
| CVE-2025-3203 | MEDIUM | 5.3 | 0.5% | Apr 4, 2025 | A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the func... |
| CVE-2025-3198 | MEDIUM | 5.5 | 0.2% | Apr 4, 2025 | A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability i... |
| CVE-2025-3196 | MEDIUM | 5.5 | 0.3% | Apr 4, 2025 | A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the ... |
| CVE-2025-26401 | MEDIUM | 6.5 | 0.2% | Apr 4, 2025 | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authen... |
| CVE-2025-25061 | MEDIUM | 5.8 | 0.4% | Apr 4, 2025 | Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi... |
| CVE-2025-24317 | MEDIUM | 5.3 | 0.5% | Apr 4, 2025 | Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi... |
| CVE-2025-24310 | MEDIUM | 4.3 | 0.3% | Apr 4, 2025 | Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote... |
| CVE-2025-29796 | MEDIUM | 4.7 | 0.5% | Apr 4, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ... |
| CVE-2025-25001 | MEDIUM | 4.3 | 0.6% | Apr 4, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ... |
| CVE-2025-0279 | MEDIUM | 4.3 | 0.3% | Apr 3, 2025 | HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal... |
| CVE-2025-0278 | MEDIUM | 4.3 | 0.3% | Apr 3, 2025 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reve... |
| CVE-2025-31486 | MEDIUM | 5.3 | 35.2% | Apr 3, 2025 | Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By ... |
| CVE-2025-31483 | MEDIUM | 4.8 | 0.4% | Apr 3, 2025 | Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP o... |
| CVE-2025-31127 | MEDIUM | 5.3 | 0.2% | Apr 3, 2025 | Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25... |
| CVE-2025-31126 | MEDIUM | 5.3 | 0.2% | Apr 3, 2025 | Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entit... |
| CVE-2025-3169 | MEDIUM | 5 | 0.3% | Apr 3, 2025 | A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-3165 | MEDIUM | 5.3 | 0.2% | Apr 3, 2025 | A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of... |
| CVE-2025-3157 | MEDIUM | 4.8 | 0.3% | Apr 3, 2025 | A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects som... |
| CVE-2025-32053 | MEDIUM | 6.5 | 0.6% | Apr 3, 2025 | A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now