2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5074 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio... |
| CVE-2025-5073 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u... |
| CVE-2025-41403 | HIGH | 8.3 | 1.4% | May 22, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching ... |
| CVE-2025-3836 | HIGH | 8.3 | 4.6% | May 22, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev... |
| CVE-2025-3444 | MEDIUM | 6.5 | 1.2% | May 22, 2025 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated L... |
| CVE-2025-4419 | MEDIUM | 4.3 | 0.4% | May 22, 2025 | The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 vi... |
| CVE-2025-4405 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all v... |
| CVE-2025-4280 | MEDIUM | 4.8 | 0.1% | May 22, 2025 | MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissi... |
| CVE-2025-4123 | MEDIUM | 6.1 | 94.4% | May 22, 2025 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire... |
| CVE-2025-4133 | MEDIUM | 5.4 | 0.3% | May 22, 2025 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts whe... |
| CVE-2025-5062 | MEDIUM | 6.1 | 0.4% | May 22, 2025 | The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p... |
| CVE-2025-3887 | HIGH | 8.8 | 0.7% | May 22, 2025 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-3885 | MEDIUM | 6.5 | 0.2% | May 22, 2025 | Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows netwo... |
| CVE-2025-3884 | HIGH | 7.5 | 1.6% | May 22, 2025 | Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-3883 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw... |
| CVE-2025-3882 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-3881 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2025-3486 | HIGH | 8.8 | 1.6% | May 22, 2025 | Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-3484 | CRITICAL | 9.8 | 0.8% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3483 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3482 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3481 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3480 | MEDIUM | 6.5 | 0.1% | May 22, 2025 | MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability... |
| CVE-2025-2759 | HIGH | 7.8 | 0.1% | May 22, 2025 | GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta... |
| CVE-2025-5059 | HIGH | 7.2 | 0.4% | May 21, 2025 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now