2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47436 | CRITICAL | 9.8 | 0.5% | May 14, 2025 | Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompre... |
| CVE-2025-3600 | HIGH | 7.5 | 19.1% | May 14, 2025 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may... |
| CVE-2025-22756 | — | — | — | May 14, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-47445 | CRITICAL | 9.8 | 4.7% | May 14, 2025 | Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev... |
| CVE-2025-3931 | HIGH | 7.8 | 0.2% | May 14, 2025 | A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's ... |
| CVE-2025-3769 | MEDIUM | 5.3 | 0.3% | May 14, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc... |
| CVE-2025-4430 | HIGH | 8.6 | 0.3% | May 14, 2025 | Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in ve... |
| CVE-2025-47292 | CRITICAL | 9.5 | 0.6% | May 14, 2025 | Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175b... |
| CVE-2025-3834 | HIGH | 8.1 | 1.3% | May 14, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU Histo... |
| CVE-2025-3833 | HIGH | 8.1 | 27.8% | May 14, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MF... |
| CVE-2025-26864 | HIGH | 7.5 | 0.7% | May 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili... |
| CVE-2025-26795 | HIGH | 7.5 | 0.7% | May 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili... |
| CVE-2025-2875 | HIGH | 8.7 | 0.3% | May 14, 2025 | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of... |
| CVE-2025-0020 | — | — | — | May 14, 2025 | Rejected reason: “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it i... |
| CVE-2025-47899 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47898 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47897 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47896 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47895 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47894 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47893 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47892 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-47891 | — | — | — | May 14, 2025 | Rejected reason: Not used |
| CVE-2025-4520 | MEDIUM | 4.3 | 0.3% | May 14, 2025 | The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2025-3623 | CRITICAL | 9.1 | 0.8% | May 14, 2025 | The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now