2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47794 | MEDIUM | 4.3 | 0.4% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Ne... |
| CVE-2025-47793 | MEDIUM | 6.5 | 0.7% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured fo... |
| CVE-2025-47792 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty app... |
| CVE-2025-47791 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and N... |
| CVE-2025-4780 | CRITICAL | 9.8 | 0.3% | May 16, 2025 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue ... |
| CVE-2025-4778 | HIGH | 8.8 | 0.3% | May 16, 2025 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vul... |
| CVE-2025-4600 | HIGH | 7.5 | 0.2% | May 16, 2025 | A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling... |
| CVE-2025-4211 | HIGH | 7.3 | 0.2% | May 16, 2025 | Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib modu... |
| CVE-2025-47790 | MEDIUM | 6.4 | 0.3% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextc... |
| CVE-2025-32962 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for ... |
| CVE-2025-4777 | HIGH | 8.8 | 0.3% | May 16, 2025 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This a... |
| CVE-2025-4773 | CRITICAL | 9.8 | 0.4% | May 16, 2025 | A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issu... |
| CVE-2025-40907 | MEDIUM | 5.3 | 0.5% | May 16, 2025 | FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The in... |
| CVE-2025-40629 | HIGH | 8.7 | 0.8% | May 16, 2025 | PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform di... |
| CVE-2025-37890 | HIGH | 7.8 | 0.2% | May 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class w... |
| CVE-2025-2306 | MEDIUM | 5.9 | 0.4% | May 16, 2025 | An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows us... |
| CVE-2025-2305 | HIGH | 8.6 | 0.3% | May 16, 2025 | A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica... |
| CVE-2025-4772 | CRITICAL | 9.8 | 0.5% | May 16, 2025 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this... |
| CVE-2025-4771 | CRITICAL | 9.8 | 0.4% | May 16, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is a... |
| CVE-2025-4770 | HIGH | 8.8 | 0.3% | May 16, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. Th... |
| CVE-2025-4769 | HIGH | 7.3 | 0.2% | May 16, 2025 | A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknow... |
| CVE-2025-40632 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to mod... |
| CVE-2025-40631 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header a... |
| CVE-2025-40630 | MEDIUM | 6.1 | 0.4% | May 16, 2025 | Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to... |
| CVE-2025-4768 | MEDIUM | 6.3 | 0.3% | May 16, 2025 | A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now