2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44897 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_up... |
| CVE-2025-44896 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_... |
| CVE-2025-44894 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiu... |
| CVE-2025-44891 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_... |
| CVE-2025-44883 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_server... |
| CVE-2025-44882 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to ... |
| CVE-2025-44880 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu... |
| CVE-2025-4997 | HIGH | 7.1 | 0.4% | May 20, 2025 | A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function U... |
| CVE-2025-48056 | MEDIUM | 5.3 | 0.2% | May 20, 2025 | Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to versio... |
| CVE-2025-44893 | CRITICAL | 9.8 | 0.6% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt... |
| CVE-2025-44890 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv... |
| CVE-2025-44888 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_gl... |
| CVE-2025-44887 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_p... |
| CVE-2025-44886 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_m... |
| CVE-2025-44885 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_rem... |
| CVE-2025-44884 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function. |
| CVE-2025-44881 | CRITICAL | 9.8 | 2.6% | May 20, 2025 | A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu... |
| CVE-2025-4996 | MEDIUM | 4.8 | 0.3% | May 20, 2025 | A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some... |
| CVE-2025-47290 | MEDIUM | 5.9 | 0.4% | May 20, 2025 | containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0.... |
| CVE-2025-4364 | HIGH | 8.7 | 0.4% | May 20, 2025 | The affected products could allow an unauthenticated attacker to access system information that could enable further acc... |
| CVE-2025-48391 | HIGH | 7.5 | 0.3% | May 20, 2025 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API |
| CVE-2025-47854 | MEDIUM | 6.1 | 0.2% | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page |
| CVE-2025-47853 | MEDIUM | 5.4 | 0.6% | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible |
| CVE-2025-47852 | MEDIUM | 5.4 | 0.6% | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible |
| CVE-2025-47851 | MEDIUM | 5.4 | 2.3% | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now