2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20247 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
| CVE-2025-20246 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
| CVE-2025-20242 | CRITICAL | 9.1 | 2.3% | May 21, 2025 | A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthent... |
| CVE-2025-20152 | HIGH | 8.6 | 0.6% | May 21, 2025 | A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen... |
| CVE-2025-20114 | MEDIUM | 4.3 | 0.3% | May 21, 2025 | A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform... |
| CVE-2025-20113 | HIGH | 7.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges... |
| CVE-2025-20112 | MEDIUM | 5.1 | 0.1% | May 21, 2025 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authentica... |
| CVE-2025-0372 | MEDIUM | 5.9 | 0.1% | May 21, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwo... |
| CVE-2025-4008 | HIGH | 8.8 | 93.9% | May 21, 2025 | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer ... |
| CVE-2025-48207 | HIGH | 8.6 | 0.3% | May 21, 2025 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48206 | MEDIUM | 6.1 | 0.2% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 allows XSS. |
| CVE-2025-48205 | HIGH | 8.6 | 0.3% | May 21, 2025 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48204 | MEDIUM | 6.8 | 1.5% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 allows command injection. |
| CVE-2025-48203 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The cs_seo extension through 9.2.0 for TYPO3 allows XSS. |
| CVE-2025-48202 | MEDIUM | 5.3 | 0.2% | May 21, 2025 | The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48201 | HIGH | 8.6 | 0.3% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. |
| CVE-2025-48200 | CRITICAL | 10 | 0.6% | May 21, 2025 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution. |
| CVE-2025-27998 | HIGH | 8.4 | 0.2% | May 21, 2025 | An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe... |
| CVE-2025-27997 | HIGH | 8.4 | 0.2% | May 21, 2025 | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script... |
| CVE-2025-5029 | MEDIUM | 5.4 | 0.4% | May 21, 2025 | A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classifie... |
| CVE-2025-44895 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4B... |
| CVE-2025-44892 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_p... |
| CVE-2025-48417 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | The certificate and private key used for providing transport layer security for connections to the web interface (TCP po... |
| CVE-2025-48416 | HIGH | 8.1 | 0.5% | May 21, 2025 | An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image fo... |
| CVE-2025-48415 | MEDIUM | 6.2 | 0.2% | May 21, 2025 | A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now