2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47706 | MEDIUM | 4.8 | 0.2% | May 14, 2025 | Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services w... |
| CVE-2025-47705 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remo... |
| CVE-2025-47704 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki... |
| CVE-2025-47703 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-47702 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Prov... |
| CVE-2025-47701 | HIGH | 8.8 | 0.2% | May 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This is... |
| CVE-2025-44186 | MEDIUM | 5.4 | 0.1% | May 14, 2025 | SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operatio... |
| CVE-2025-44184 | MEDIUM | 4.8 | 0.2% | May 14, 2025 | SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi... |
| CVE-2025-40595 | HIGH | 7.2 | 0.3% | May 14, 2025 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By... |
| CVE-2025-3932 | MEDIUM | 6.5 | 0.3% | May 14, 2025 | It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach... |
| CVE-2025-3909 | HIGH | 8.1 | 0.4% | May 14, 2025 | Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the fil... |
| CVE-2025-3877 | — | — | — | May 14, 2025 | Rejected reason: This CVE was marked as fixed, but due to other code landing - was not actually fixed. It was subsequen... |
| CVE-2025-3875 | HIGH | 7.5 | 0.3% | May 14, 2025 | Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t... |
| CVE-2025-26785 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-26784 | MEDIUM | 6.5 | 0.2% | May 14, 2025 | An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-47782 | HIGH | 8.9 | 0.4% | May 14, 2025 | motionEye is an online interface for the software motion, a video surveillance program with motion detection. In version... |
| CVE-2025-47781 | CRITICAL | 9.8 | 0.5% | May 14, 2025 | Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application featu... |
| CVE-2025-47778 | MEDIUM | 6.1 | 0.4% | May 14, 2025 | Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,... |
| CVE-2025-47777 | CRITICAL | 9.6 | 0.8% | May 14, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to ... |
| CVE-2025-47775 | HIGH | 8.6 | 0.4% | May 14, 2025 | Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tc... |
| CVE-2025-24969 | MEDIUM | 5 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts pictur... |
| CVE-2025-24785 | MEDIUM | 4.3 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a... |
| CVE-2025-24026 | MEDIUM | 5.3 | 0.3% | May 14, 2025 | iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of ... |
| CVE-2025-24022 | HIGH | 8.5 | 0.5% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is po... |
| CVE-2025-24021 | MEDIUM | 5 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now