2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5100 | HIGH | 8 | 0.2% | May 23, 2025 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory cor... |
| CVE-2025-5099 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c... |
| CVE-2025-5098 | CRITICAL | 9.1 | 0.3% | May 23, 2025 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's... |
| CVE-2025-2394 | MEDIUM | 4.7 | 0.2% | May 23, 2025 | Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alib... |
| CVE-2025-4692 | MEDIUM | 6.8 | 0.3% | May 23, 2025 | Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation b... |
| CVE-2025-4642 | — | — | — | May 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-4562 | — | — | — | May 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-4338 | MEDIUM | 6.9 | 0.2% | May 22, 2025 | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the netwo... |
| CVE-2025-48371 | HIGH | 8.8 | 0.4% | May 22, 2025 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg... |
| CVE-2025-4975 | MEDIUM | 4.8 | 0.1% | May 22, 2025 | When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notific... |
| CVE-2025-47181 | HIGH | 8.8 | 0.5% | May 22, 2025 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a... |
| CVE-2025-48374 | MEDIUM | 5.5 | 0.2% | May 22, 2025 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to v... |
| CVE-2025-48373 | CRITICAL | 9.1 | 0.3% | May 22, 2025 | Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ... |
| CVE-2025-48372 | HIGH | 7.3 | 0.2% | May 22, 2025 | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time... |
| CVE-2025-48369 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48368 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48366 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48075 | HIGH | 7.5 | 0.4% | May 22, 2025 | Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber... |
| CVE-2025-48066 | MEDIUM | 5.5 | 0.1% | May 22, 2025 | wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an ... |
| CVE-2025-30173 | MEDIUM | 6.7 | 0.3% | May 22, 2025 | File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff... |
| CVE-2025-30172 | HIGH | 8.9 | 0.5% | May 22, 2025 | Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This... |
| CVE-2025-30171 | CRITICAL | 9 | 0.3% | May 22, 2025 | System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator ... |
| CVE-2025-30170 | MEDIUM | 5.9 | 0.3% | May 22, 2025 | Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf... |
| CVE-2025-30169 | MEDIUM | 6.7 | 0.3% | May 22, 2025 | File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become... |
| CVE-2025-2410 | CRITICAL | 9.1 | 0.4% | May 22, 2025 | Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now