2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0138 | LOW | 2 | 0.3% | May 14, 2025 | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet... |
| CVE-2025-0137 | MEDIUM | 4.8 | 0.3% | May 14, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
| CVE-2025-0136 | MEDIUM | 5.3 | 0.1% | May 14, 2025 | Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, P... |
| CVE-2025-0135 | LOW | 3.3 | 0.1% | May 14, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0134 | MEDIUM | 6.5 | 0.4% | May 14, 2025 | A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute a... |
| CVE-2025-0133 | LOW | 2.7 | 43.5% | May 14, 2025 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw... |
| CVE-2025-0132 | MEDIUM | 6.9 | 0.4% | May 14, 2025 | A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to dis... |
| CVE-2025-0131 | HIGH | 7.1 | 0.1% | May 14, 2025 | An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto N... |
| CVE-2025-4664 | MEDIUM | 4.3 | 5.3% | May 14, 2025 | Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro... |
| CVE-2025-4639 | HIGH | 8.8 | 0.4% | May 14, 2025 | CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe... |
| CVE-2025-4638 | CRITICAL | 9.8 | 0.4% | May 14, 2025 | A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (P... |
| CVE-2025-4637 | HIGH | 8.7 | 0.4% | May 14, 2025 | Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file... |
| CVE-2025-46786 | MEDIUM | 6.1 | 0.3% | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc... |
| CVE-2025-46785 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service ... |
| CVE-2025-30668 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network... |
| CVE-2025-30667 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-30666 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-30665 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-30664 | HIGH | 8.2 | 0.2% | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege v... |
| CVE-2025-30663 | HIGH | 7 | 0.1% | May 14, 2025 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escal... |
| CVE-2025-0130 | HIGH | 7.5 | 0.4% | May 14, 2025 | A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenti... |
| CVE-2025-47710 | HIGH | 7.4 | 0.3% | May 14, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
| CVE-2025-47709 | MEDIUM | 6.5 | 0.2% | May 14, 2025 | Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affect... |
| CVE-2025-47708 | HIGH | 8.8 | 0.2% | May 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forg... |
| CVE-2025-47707 | HIGH | 7.5 | 0.4% | May 14, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now