2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34025 | HIGH | 8.8 | 0.4% | May 21, 2025 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab... |
| CVE-2025-5057 | CRITICAL | 9.8 | 0.4% | May 21, 2025 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue... |
| CVE-2025-5056 | CRITICAL | 9.8 | 0.4% | May 21, 2025 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vu... |
| CVE-2025-48070 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer tha... |
| CVE-2025-47947 | HIGH | 7.5 | 0.6% | May 21, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ... |
| CVE-2025-47942 | MEDIUM | 5.3 | 0.4% | May 21, 2025 | The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxap... |
| CVE-2025-34027 | CRITICAL | 9 | 32.3% | May 21, 2025 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy ... |
| CVE-2025-34026 | HIGH | 7.5 | 83.4% | May 21, 2025 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy ... |
| CVE-2025-5053 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is... |
| CVE-2025-5052 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-45753 | HIGH | 7.2 | 0.4% | May 21, 2025 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P... |
| CVE-2025-44040 | HIGH | 7.2 | 0.4% | May 21, 2025 | An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi... |
| CVE-2025-5051 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th... |
| CVE-2025-46412 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authenticati... |
| CVE-2025-45755 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the S... |
| CVE-2025-41426 | CRITICAL | 9.8 | 0.7% | May 21, 2025 | Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerabili... |
| CVE-2025-36535 | CRITICAL | 10 | 1.0% | May 21, 2025 | The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead t... |
| CVE-2025-5050 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown pr... |
| CVE-2025-5049 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unkn... |
| CVE-2025-45752 | HIGH | 7.2 | 0.5% | May 21, 2025 | A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t... |
| CVE-2025-44083 | CRITICAL | 9.8 | 0.8% | May 21, 2025 | An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication |
| CVE-2025-3751 | HIGH | 7 | 0.3% | May 21, 2025 | The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection atta... |
| CVE-2025-2261 | HIGH | 7 | 0.3% | May 21, 2025 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within ... |
| CVE-2025-27558 | CRITICAL | 9.1 | 0.3% | May 21, 2025 | IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Ac... |
| CVE-2025-5033 | MEDIUM | 5.3 | 0.2% | May 21, 2025 | A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unk... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now