2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2826 | LOW | 2.6 | 0.5% | May 27, 2025 | n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 st... |
| CVE-2025-2796 | MEDIUM | 5.3 | 0.2% | May 27, 2025 | On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection confi... |
| CVE-2025-40911 | MEDIUM | 6.5 | 0.3% | May 27, 2025 | Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address s... |
| CVE-2025-32440 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the aut... |
| CVE-2025-5283 | MEDIUM | 5.4 | 0.5% | May 27, 2025 | Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-5281 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially... |
| CVE-2025-5280 | HIGH | 8.8 | 2.2% | May 27, 2025 | Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-5279 | HIGH | 7 | 0.2% | May 27, 2025 | When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the drive... |
| CVE-2025-5278 | MEDIUM | 4.4 | 0.3% | May 27, 2025 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The... |
| CVE-2025-5222 | HIGH | 7 | 0.4% | May 27, 2025 | A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'su... |
| CVE-2025-5198 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a s... |
| CVE-2025-5067 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform U... |
| CVE-2025-5066 | MEDIUM | 6.5 | 0.4% | May 27, 2025 | Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker wh... |
| CVE-2025-5065 | MEDIUM | 6.5 | 0.4% | May 27, 2025 | Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t... |
| CVE-2025-5064 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t... |
| CVE-2025-5063 | HIGH | 8.8 | 2.9% | May 27, 2025 | Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit h... |
| CVE-2025-46173 | MEDIUM | 6.1 | 0.3% | May 27, 2025 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the fee... |
| CVE-2025-45529 | HIGH | 7.1 | 0.3% | May 27, 2025 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbit... |
| CVE-2025-2872 | — | — | — | May 27, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-47577. Reason: This candidate is a ... |
| CVE-2025-5252 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability af... |
| CVE-2025-45475 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. |
| CVE-2025-5251 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unk... |
| CVE-2025-5250 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is so... |
| CVE-2025-5249 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulner... |
| CVE-2025-48057 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and gener... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now