2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26685 | MEDIUM | 6.5 | 0.6% | May 13, 2025 | Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a... |
| CVE-2025-26684 | MEDIUM | 6.7 | 0.4% | May 13, 2025 | External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil... |
| CVE-2025-26677 | HIGH | 7.5 | 1.4% | May 13, 2025 | Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over... |
| CVE-2025-24063 | HIGH | 7.8 | 0.6% | May 13, 2025 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-21264 | HIGH | 7.1 | 0.6% | May 13, 2025 | Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se... |
| CVE-2025-0035 | HIGH | 7.3 | 0.2% | May 13, 2025 | Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential... |
| CVE-2025-4428 | HIGH | 8.8 | 87.5% | May 13, 2025 | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms all... |
| CVE-2025-4427 | HIGH | 7.5 | 99.6% | May 13, 2025 | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a... |
| CVE-2025-47278 | LOW | 1.8 | 0.2% | May 13, 2025 | Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura... |
| CVE-2025-47276 | HIGH | 7.5 | 0.2% | May 13, 2025 | Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating syste... |
| CVE-2025-47204 | MEDIUM | 6.1 | 0.4% | May 13, 2025 | An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour... |
| CVE-2025-46721 | MEDIUM | 6.1 | 0.2% | May 13, 2025 | nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 all... |
| CVE-2025-45858 | CRITICAL | 9.8 | 9.1% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f... |
| CVE-2025-45857 | CRITICAL | 9.8 | 0.9% | May 13, 2025 | EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in... |
| CVE-2025-31493 | CRITICAL | 9.1 | 0.5% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-30207 | HIGH | 7.5 | 0.5% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-28056 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component. |
| CVE-2025-28055 | HIGH | 7.5 | 0.5% | May 13, 2025 | upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit |
| CVE-2025-22462 | CRITICAL | 9.8 | 1.9% | May 13, 2025 | An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se... |
| CVE-2025-45867 | MEDIUM | 5.4 | 3.4% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the f... |
| CVE-2025-45866 | MEDIUM | 5.4 | 0.3% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the f... |
| CVE-2025-45864 | MEDIUM | 5.4 | 3.4% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the... |
| CVE-2025-45859 | MEDIUM | 5.4 | 3.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formM... |
| CVE-2025-44831 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface. |
| CVE-2025-44039 | MEDIUM | 5.1 | 0.2% | May 13, 2025 | CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now