2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23247 | HIGH | 7.8 | 0.3% | May 27, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the len... |
| CVE-2025-22377 | MEDIUM | 6.5 | 0.3% | May 27, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-5248 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affect... |
| CVE-2025-48370 | LOW | 2.7 | 0.7% | May 27, 2025 | auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI... |
| CVE-2025-27701 | MEDIUM | 5.5 | 0.1% | May 27, 2025 | In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after ca... |
| CVE-2025-27700 | HIGH | 8.4 | 0.1% | May 27, 2025 | There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of ... |
| CVE-2025-5247 | HIGH | 7.3 | 0.4% | May 27, 2025 | A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function ... |
| CVE-2025-5246 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability ... |
| CVE-2025-5245 | HIGH | 7.8 | 0.2% | May 27, 2025 | A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_s... |
| CVE-2025-48383 | HIGH | 8.2 | 0.3% | May 27, 2025 | Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses li... |
| CVE-2025-3704 | MEDIUM | 5.9 | 0.2% | May 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions V... |
| CVE-2025-2236 | LOW | 2.1 | 0.2% | May 27, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica... |
| CVE-2025-48798 | HIGH | 7.3 | 0.2% | May 27, 2025 | A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special... |
| CVE-2025-48797 | HIGH | 7.3 | 0.2% | May 27, 2025 | A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been... |
| CVE-2025-48796 | HIGH | 7.3 | 0.2% | May 27, 2025 | A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.AN... |
| CVE-2025-5272 | HIGH | 7.3 | 0.3% | May 27, 2025 | Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-5271 | MEDIUM | 6.5 | 0.2% | May 27, 2025 | Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab... |
| CVE-2025-5270 | HIGH | 7.5 | 0.2% | May 27, 2025 | In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed... |
| CVE-2025-5269 | HIGH | 8.1 | 0.4% | May 27, 2025 | Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a... |
| CVE-2025-5268 | HIGH | 8.1 | 0.4% | May 27, 2025 | Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu... |
| CVE-2025-5267 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious... |
| CVE-2025-5266 | MEDIUM | 4.3 | 0.3% | May 27, 2025 | Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak... |
| CVE-2025-5265 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in... |
| CVE-2025-5264 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into... |
| CVE-2025-5263 | MEDIUM | 4.3 | 0.2% | May 27, 2025 | Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now