2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43289 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO... |
| CVE-2025-68709 | MEDIUM | 5.2 | 0.2% | May 26, 2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe... |
| CVE-2025-33221 | MEDIUM | 6 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an i... |
| CVE-2025-36148 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transacti... |
| CVE-2025-36145 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could... |
| CVE-2025-14290 | MEDIUM | 5.4 | 0.2% | May 26, 2026 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM... |
| CVE-2025-13755 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) store... |
| CVE-2025-62745 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team S... |
| CVE-2025-46371 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ... |
| CVE-2025-32751 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low... |
| CVE-2025-32746 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un... |
| CVE-2025-32745 | MEDIUM | 6.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthentica... |
| CVE-2025-31985 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty... |
| CVE-2025-15369 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-15645 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t... |
| CVE-2025-57798 | MEDIUM | 5.5 | 0.2% | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1... |
| CVE-2025-40904 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an... |
| CVE-2025-40903 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid... |
| CVE-2025-40902 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p... |
| CVE-2025-40901 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation... |
| CVE-2025-40900 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-65954 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel... |
| CVE-2025-4202 | MEDIUM | 4.3 | 0.2% | May 16, 2026 | The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo... |
| CVE-2025-67031 | MEDIUM | 6.3 | 0.3% | May 15, 2026 | ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera... |
| CVE-2025-67437 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now