2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5262 | HIGH | 7.5 | 0.4% | May 27, 2025 | A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder ... |
| CVE-2025-5244 | HIGH | 7.8 | 0.2% | May 27, 2025 | A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the funct... |
| CVE-2025-5117 | HIGH | 8.8 | 0.4% | May 27, 2025 | The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of ... |
| CVE-2025-4412 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it ... |
| CVE-2025-41653 | HIGH | 7.5 | 0.5% | May 27, 2025 | An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionalit... |
| CVE-2025-41652 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated r... |
| CVE-2025-41651 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbit... |
| CVE-2025-41650 | HIGH | 7.5 | 0.4% | May 27, 2025 | An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt... |
| CVE-2025-41649 | HIGH | 7.5 | 0.4% | May 27, 2025 | An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer... |
| CVE-2025-2407 | CRITICAL | 9.3 | 0.4% | May 27, 2025 | Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted acc... |
| CVE-2025-23393 | MEDIUM | 5.6 | 0.3% | May 27, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows ... |
| CVE-2025-5232 | HIGH | 7.2 | 0.3% | May 27, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1... |
| CVE-2025-5231 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability... |
| CVE-2025-48382 | MEDIUM | 5.5 | 0.1% | May 27, 2025 | Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes... |
| CVE-2025-48054 | MEDIUM | 6.8 | 0.6% | May 27, 2025 | Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnera... |
| CVE-2025-5230 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unkn... |
| CVE-2025-5229 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by... |
| CVE-2025-5228 | HIGH | 8.8 | 2.0% | May 27, 2025 | A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function... |
| CVE-2025-5227 | HIGH | 7.3 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown proces... |
| CVE-2025-48828 | HIGH | 8.1 | 48.4% | May 27, 2025 | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t... |
| CVE-2025-48827 | CRITICAL | 9.8 | 69.6% | May 27, 2025 | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' ... |
| CVE-2025-48794 | — | — | — | May 27, 2025 | Rejected reason: Not used |
| CVE-2025-48793 | — | — | — | May 27, 2025 | Rejected reason: Not used |
| CVE-2025-48792 | — | — | — | May 27, 2025 | Rejected reason: Not used |
| CVE-2025-48791 | — | — | — | May 27, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now