2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2409 | CRITICAL | 9.1 | 0.4% | May 22, 2025 | File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c... |
| CVE-2025-48061 | MEDIUM | 5.6 | 0.1% | May 22, 2025 | wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in... |
| CVE-2025-47780 | HIGH | 7.8 | 0.2% | May 22, 2025 | Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste... |
| CVE-2025-47779 | MEDIUM | 6.5 | 0.4% | May 22, 2025 | Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste... |
| CVE-2025-46716 | MEDIUM | 5.5 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-46715 | HIGH | 7.8 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-45472 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou... |
| CVE-2025-43596 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands ... |
| CVE-2025-33138 | MEDIUM | 6.1 | 0.2% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-33137 | HIGH | 8.8 | 0.3% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau... |
| CVE-2025-33136 | HIGH | 8.8 | 0.3% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau... |
| CVE-2025-5081 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerab... |
| CVE-2025-4366 | MEDIUM | 6.1 | 0.4% | May 22, 2025 | A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP r... |
| CVE-2025-45468 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust... |
| CVE-2025-2506 | MEDIUM | 5.3 | 0.3% | May 22, 2025 | When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user w... |
| CVE-2025-23183 | MEDIUM | 6.1 | 0.2% | May 22, 2025 | CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2025-23182 | MEDIUM | 4.3 | 0.2% | May 22, 2025 | CWE-203: Observable Discrepancy |
| CVE-2025-5080 | HIGH | 8.8 | 0.8% | May 22, 2025 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFil... |
| CVE-2025-5079 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown f... |
| CVE-2025-5024 | HIGH | 7.4 | 0.8% | May 22, 2025 | A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated atta... |
| CVE-2025-45471 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl... |
| CVE-2025-32915 | MEDIUM | 5.5 | 0.1% | May 22, 2025 | Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.... |
| CVE-2025-32815 | MEDIUM | 6.5 | 32.8% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur. |
| CVE-2025-32814 | CRITICAL | 9.8 | 35.8% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. |
| CVE-2025-32813 | HIGH | 7.2 | 42.3% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now