2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46717 | LOW | 3.3 | 0.3% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l... |
| CVE-2025-46611 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted sc... |
| CVE-2025-46610 | HIGH | 8.8 | 0.2% | May 12, 2025 | ARTEC EMA Mail 6.92 allows CSRF. |
| CVE-2025-26846 | CRITICAL | 9.8 | 0.4% | May 12, 2025 | An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to ... |
| CVE-2025-26841 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code ... |
| CVE-2025-45835 | HIGH | 7.5 | 0.4% | May 12, 2025 | A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_... |
| CVE-2025-40627 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr... |
| CVE-2025-40626 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr... |
| CVE-2025-47271 | MEDIUM | 6.3 | 0.4% | May 12, 2025 | The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance... |
| CVE-2025-47270 | HIGH | 7.5 | 0.6% | May 12, 2025 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2025-46729 | LOW | 2.1 | 0.4% | May 12, 2025 | julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the... |
| CVE-2025-32390 | HIGH | 8.5 | 0.3% | May 12, 2025 | EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Know... |
| CVE-2025-22247 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a... |
| CVE-2025-1533 | HIGH | 8.2 | 0.3% | May 12, 2025 | A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu... |
| CVE-2025-41393 | MEDIUM | 6.1 | 0.6% | May 12, 2025 | Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implem... |
| CVE-2025-3496 | HIGH | 7.5 | 0.5% | May 12, 2025 | An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluet... |
| CVE-2025-4561 | HIGH | 8.8 | 0.6% | May 12, 2025 | The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to up... |
| CVE-2025-4560 | MEDIUM | 6.9 | 0.3% | May 12, 2025 | The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to a... |
| CVE-2025-4559 | CRITICAL | 9.8 | 0.5% | May 12, 2025 | The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arb... |
| CVE-2025-3649 | MEDIUM | 6.8 | 0.4% | May 12, 2025 | The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs,... |
| CVE-2025-3597 | MEDIUM | 5.9 | 0.3% | May 12, 2025 | The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executi... |
| CVE-2025-4558 | CRITICAL | 9.8 | 0.4% | May 12, 2025 | The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to... |
| CVE-2025-4557 | CRITICAL | 9.1 | 0.5% | May 12, 2025 | The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthe... |
| CVE-2025-4556 | CRITICAL | 9.8 | 0.6% | May 12, 2025 | The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerabilit... |
| CVE-2025-4555 | CRITICAL | 9.8 | 0.5% | May 12, 2025 | The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerabilit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now