2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3710 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-4455 | HIGH | 7.3 | 0.2% | May 9, 2025 | A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects s... |
| CVE-2025-4454 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4453 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function form... |
| CVE-2025-4434 | — | — | — | May 9, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-3811 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2025-3810 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2025-4452 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this issue is the function ... |
| CVE-2025-4451 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is ... |
| CVE-2025-4450 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.04B04. Affected is the function formSe... |
| CVE-2025-4449 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.04B04. This issue affects the fun... |
| CVE-2025-4448 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability classified as critical was found in D-Link DIR-619L 2.04B04. This vulnerability affects the function for... |
| CVE-2025-4446 | HIGH | 8.6 | 0.5% | May 9, 2025 | A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the... |
| CVE-2025-4445 | CRITICAL | 9.8 | 6.5% | May 9, 2025 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. ... |
| CVE-2025-4443 | CRITICAL | 9.8 | 53.8% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub... |
| CVE-2025-4442 | CRITICAL | 9.8 | 2.1% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4441 | CRITICAL | 9.8 | 2.1% | May 8, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form... |
| CVE-2025-4440 | HIGH | 8.6 | 0.5% | May 8, 2025 | A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the funct... |
| CVE-2025-4107 | — | — | — | May 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-47733 | HIGH | 7.5 | 1.5% | May 8, 2025 | Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over ... |
| CVE-2025-47732 | CRITICAL | 9.8 | 2.9% | May 8, 2025 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. |
| CVE-2025-33072 | HIGH | 7.5 | 1.4% | May 8, 2025 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-31946 | MEDIUM | 6.9 | 0.2% | May 8, 2025 | Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a cr... |
| CVE-2025-29972 | CRITICAL | 9.8 | 2.6% | May 8, 2025 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing ... |
| CVE-2025-29827 | HIGH | 8.8 | 1.2% | May 8, 2025 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now