2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48928 | MEDIUM | 4 | 0.4% | May 28, 2025 | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent... |
| CVE-2025-48927 | MEDIUM | 5.3 | 7.9% | May 28, 2025 | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap... |
| CVE-2025-48926 | HIGH | 7.5 | 0.2% | May 28, 2025 | The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, ... |
| CVE-2025-48925 | HIGH | 7.5 | 0.2% | May 28, 2025 | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then... |
| CVE-2025-48746 | MEDIUM | 6.5 | 0.2% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe... |
| CVE-2025-36572 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image f... |
| CVE-2025-32802 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M... |
| CVE-2025-32801 | HIGH | 7.8 | 0.2% | May 28, 2025 | Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a... |
| CVE-2025-45343 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of ... |
| CVE-2025-3357 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code du... |
| CVE-2025-5277 | CRITICAL | 9.6 | 1.3% | May 28, 2025 | aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M... |
| CVE-2025-4134 | HIGH | 7.3 | 0.2% | May 28, 2025 | Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o... |
| CVE-2025-48734 | HIGH | 8.8 | 1.5% | May 28, 2025 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2.... |
| CVE-2025-45997 | HIGH | 8.6 | 0.4% | May 28, 2025 | Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa... |
| CVE-2025-40651 | MEDIUM | 5.1 | 0.4% | May 28, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute ... |
| CVE-2025-4493 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT req... |
| CVE-2025-5299 | HIGH | 7.3 | 0.5% | May 28, 2025 | A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi... |
| CVE-2025-5298 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte... |
| CVE-2025-5297 | MEDIUM | 6.6 | 0.2% | May 28, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issu... |
| CVE-2025-3864 | LOW | 2.3 | 0.7% | May 28, 2025 | Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote a... |
| CVE-2025-5295 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code ... |
| CVE-2025-40673 | MEDIUM | 5.3 | 0.3% | May 28, 2025 | A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoi... |
| CVE-2025-4963 | MEDIUM | 6.4 | 0.2% | May 28, 2025 | The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u... |
| CVE-2025-1753 | HIGH | 7.8 | 1.0% | May 28, 2025 | LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the impro... |
| CVE-2025-5287 | HIGH | 7.5 | 2.1% | May 28, 2025 | The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now