2025 CVE Vulnerabilities
45,277 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40666 | CRITICAL | 9.8 | 0.3% | May 26, 2025 | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a... |
| CVE-2025-40665 | CRITICAL | 9.8 | 0.3% | May 26, 2025 | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a... |
| CVE-2025-40664 | CRITICAL | 9.1 | 0.5% | May 26, 2025 | Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /... |
| CVE-2025-40663 | MEDIUM | 5.1 | 0.3% | May 26, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated ... |
| CVE-2025-40653 | MEDIUM | 6.9 | 0.4% | May 26, 2025 | User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a differen... |
| CVE-2025-40652 | MEDIUM | 5.3 | 0.3% | May 26, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in the CoverManager booking software. This allows an attacker to inject ... |
| CVE-2025-40650 | HIGH | 8.7 | 0.3% | May 26, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retriev... |
| CVE-2025-5184 | HIGH | 7.5 | 0.3% | May 26, 2025 | A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified ... |
| CVE-2025-5183 | MEDIUM | 4.7 | 0.2% | May 26, 2025 | A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as proble... |
| CVE-2025-5182 | HIGH | 7.5 | 0.3% | May 26, 2025 | A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as c... |
| CVE-2025-5181 | MEDIUM | 4.1 | 0.4% | May 26, 2025 | A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor... |
| CVE-2025-5180 | HIGH | 7.3 | 0.2% | May 26, 2025 | A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue... |
| CVE-2025-5179 | LOW | 3.4 | 0.3% | May 26, 2025 | A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by ... |
| CVE-2025-5178 | CRITICAL | 9.8 | 0.4% | May 26, 2025 | A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected i... |
| CVE-2025-5177 | MEDIUM | 4.7 | 0.5% | May 26, 2025 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This... |
| CVE-2025-4057 | MEDIUM | 5.5 | 0.1% | May 26, 2025 | A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between se... |
| CVE-2025-4053 | MEDIUM | 6.8 | 0.1% | May 26, 2025 | The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel gues... |
| CVE-2025-40672 | HIGH | 8.5 | 0.1% | May 26, 2025 | A Privilege Escalation vulnerability has been found in Panloader component v3.24.0.0 by Espiral MS Group. This vulnerabi... |
| CVE-2025-40671 | CRITICAL | 9.3 | 0.4% | May 26, 2025 | SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create... |
| CVE-2025-35003 | CRITICAL | 9.8 | 1.2% | May 26, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities ... |
| CVE-2025-41655 | HIGH | 7.5 | 0.4% | May 26, 2025 | An unauthenticated remote attacker can access a URL which causes the device to reboot. |
| CVE-2025-41654 | HIGH | 8.2 | 0.4% | May 26, 2025 | An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of r... |
| CVE-2025-1985 | MEDIUM | 6.1 | 0.3% | May 26, 2025 | Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H... |
| CVE-2025-5176 | CRITICAL | 9.1 | 0.4% | May 26, 2025 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This... |
| CVE-2025-5175 | MEDIUM | 5.5 | 0.2% | May 26, 2025 | A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the functio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now