2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5020 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website... |
| CVE-2025-48069 | MEDIUM | 6.6 | 1.3% | May 21, 2025 | ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `e... |
| CVE-2025-48064 | LOW | 3.3 | 0.2% | May 21, 2025 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,... |
| CVE-2025-48063 | HIGH | 8.8 | 0.8% | May 21, 2025 | XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc... |
| CVE-2025-48060 | HIGH | 7.5 | 0.4% | May 21, 2025 | jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio... |
| CVE-2025-47291 | HIGH | 7.5 | 0.2% | May 21, 2025 | containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,... |
| CVE-2025-46822 | HIGH | 7.7 | 4.0% | May 21, 2025 | OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. P... |
| CVE-2025-2102 | MEDIUM | 5.7 | 0.1% | May 21, 2025 | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Priv... |
| CVE-2025-5032 | CRITICAL | 9.8 | 0.4% | May 21, 2025 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu... |
| CVE-2025-5031 | LOW | 3.1 | 0.4% | May 21, 2025 | A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some u... |
| CVE-2025-5030 | HIGH | 8.1 | 2.6% | May 21, 2025 | A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affect... |
| CVE-2025-4416 | HIGH | 7.5 | 0.3% | May 21, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio... |
| CVE-2025-4415 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO a... |
| CVE-2025-48012 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Cre... |
| CVE-2025-48011 | MEDIUM | 4.8 | 0.3% | May 21, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ... |
| CVE-2025-48010 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ... |
| CVE-2025-48009 | LOW | 3.1 | 0.2% | May 21, 2025 | Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single ... |
| CVE-2025-45754 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inj... |
| CVE-2025-25539 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via... |
| CVE-2025-20267 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2025-20258 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitr... |
| CVE-2025-20257 | MEDIUM | 6.5 | 0.3% | May 21, 2025 | A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual... |
| CVE-2025-20256 | HIGH | 7.2 | 0.5% | May 21, 2025 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network... |
| CVE-2025-20255 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip... |
| CVE-2025-20250 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now