2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1079 | HIGH | 7.8 | 0.2% | May 12, 2025 | Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature |
| CVE-2025-47682 | CRITICAL | 9.8 | 0.3% | May 12, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-44176 | MEDIUM | 6.5 | 6.5% | May 12, 2025 | Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function. |
| CVE-2025-44175 | MEDIUM | 5.4 | 0.2% | May 12, 2025 | Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function. |
| CVE-2025-46750 | MEDIUM | 4.4 | 0.1% | May 12, 2025 | SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and ch... |
| CVE-2025-46749 | MEDIUM | 4.3 | 0.2% | May 12, 2025 | An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ... |
| CVE-2025-46748 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated user attempting to change their password could do so without using the current password. |
| CVE-2025-46747 | MEDIUM | 5.7 | 0.3% | May 12, 2025 | An authenticated user without user-management permissions could identify other user accounts. |
| CVE-2025-46746 | MEDIUM | 5.8 | 0.2% | May 12, 2025 | An administrator could discover another account's credentials. |
| CVE-2025-46745 | MEDIUM | 6.5 | 0.3% | May 12, 2025 | An authenticated user without user-management permissions could view other users account information. |
| CVE-2025-46744 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated administrator could modify the Created By username for a user account |
| CVE-2025-46743 | MEDIUM | 6.3 | 0.1% | May 12, 2025 | An authenticated user's token could be used by another source after the user had logged out prior to the token expiring. |
| CVE-2025-46742 | MEDIUM | 4.3 | 0.2% | May 12, 2025 | Users who were required to change their password could still access system information before changing their password |
| CVE-2025-46741 | MEDIUM | 5.7 | 0.1% | May 12, 2025 | A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred. |
| CVE-2025-46740 | HIGH | 7.5 | 0.3% | May 12, 2025 | An authenticated user without user administrative permissions could change the administrator Account Name. |
| CVE-2025-46739 | HIGH | 8.1 | 0.3% | May 12, 2025 | An unauthenticated user could discover account credentials via a brute-force attack without rate limiting |
| CVE-2025-45779 | CRITICAL | 9.8 | 5.1% | May 12, 2025 | Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST par... |
| CVE-2025-3632 | HIGH | 7.5 | 0.4% | May 12, 2025 | IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardw... |
| CVE-2025-47578 | MEDIUM | 6.5 | 0.2% | May 12, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS... |
| CVE-2025-46738 | MEDIUM | 6.6 | 0.2% | May 12, 2025 | An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arb... |
| CVE-2025-46737 | HIGH | 7.4 | 0.1% | May 12, 2025 | SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data g... |
| CVE-2025-44830 | CRITICAL | 9.8 | 0.4% | May 12, 2025 | EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface. |
| CVE-2025-44022 | CRITICAL | 9.8 | 1.0% | May 12, 2025 | An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism. |
| CVE-2025-47274 | LOW | 2.4 | 0.1% | May 12, 2025 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to... |
| CVE-2025-46718 | LOW | 3.3 | 0.2% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now