2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48472 | HIGH | 8.1 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that... |
| CVE-2025-48471 | CRITICAL | 9.8 | 1.0% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o... |
| CVE-2025-48390 | HIGH | 7.2 | 0.8% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code ... |
| CVE-2025-48389 | HIGH | 7.2 | 0.8% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser... |
| CVE-2025-45474 | HIGH | 7.3 | 0.3% | May 29, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. |
| CVE-2025-3913 | LOW | 3.8 | 0.3% | May 29, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate pe... |
| CVE-2025-5334 | HIGH | 7.5 | 0.5% | May 29, 2025 | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des... |
| CVE-2025-5321 | CRITICAL | 9.9 | 0.5% | May 29, 2025 | A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R... |
| CVE-2025-4081 | MEDIUM | 4.8 | 0.1% | May 29, 2025 | Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints al... |
| CVE-2025-48748 | CRITICAL | 10 | 0.3% | May 29, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. |
| CVE-2025-5320 | MEDIUM | 6.3 | 0.2% | May 29, 2025 | A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is... |
| CVE-2025-46080 | MEDIUM | 5.3 | 0.4% | May 29, 2025 | HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr... |
| CVE-2025-46078 | MEDIUM | 5.3 | 0.3% | May 29, 2025 | HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server |
| CVE-2025-37999 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() aft... |
| CVE-2025-37998 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output... |
| CVE-2025-37997 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types ... |
| CVE-2025-37996 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u... |
| CVE-2025-37995 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for modul... |
| CVE-2025-37994 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer acc... |
| CVE-2025-37993 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize ... |
| CVE-2025-33043 | MEDIUM | 6.1 | 0.2% | May 29, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp... |
| CVE-2025-48047 | CRITICAL | 9.4 | 11.7% | May 29, 2025 | An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ... |
| CVE-2025-48046 | MEDIUM | 5.3 | 0.5% | May 29, 2025 | An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /co... |
| CVE-2025-48045 | HIGH | 8.7 | 0.6% | May 29, 2025 | An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials... |
| CVE-2025-48388 | MEDIUM | 6.5 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now