2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29813 | CRITICAL | 9.8 | 1.5% | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov... |
| CVE-2025-27720 | CRITICAL | 9.3 | 0.2% | May 8, 2025 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal ... |
| CVE-2025-27578 | HIGH | 8.7 | 0.8% | May 8, 2025 | Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM fil... |
| CVE-2025-1331 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t... |
| CVE-2025-1330 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on ... |
| CVE-2025-1329 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t... |
| CVE-2025-28074 | MEDIUM | 6.1 | 0.5% | May 8, 2025 | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vuln... |
| CVE-2025-4475 | — | — | — | May 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-46833 | MEDIUM | 4.6 | 0.2% | May 8, 2025 | Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versio... |
| CVE-2025-46812 | LOW | 2 | 0.6% | May 8, 2025 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to... |
| CVE-2025-46712 | LOW | 3.7 | 0.4% | May 8, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-... |
| CVE-2025-46336 | MEDIUM | 4.2 | 0.3% | May 8, 2025 | Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when usi... |
| CVE-2025-45798 | CRITICAL | 9.8 | 1.0% | May 8, 2025 | A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in... |
| CVE-2025-45797 | CRITICAL | 9.8 | 11.8% | May 8, 2025 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the impr... |
| CVE-2025-45790 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /li... |
| CVE-2025-45789 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules. |
| CVE-2025-45788 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules. |
| CVE-2025-45787 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules. |
| CVE-2025-44023 | MEDIUM | 6.5 | 0.4% | May 8, 2025 | An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account... |
| CVE-2025-28073 | MEDIUM | 6.1 | 0.5% | May 8, 2025 | phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker ... |
| CVE-2025-27695 | MEDIUM | 4.9 | 0.6% | May 8, 2025 | Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high... |
| CVE-2025-0505 | CRITICAL | 10 | 0.6% | May 8, 2025 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain ... |
| CVE-2025-4098 | HIGH | 8.4 | 0.2% | May 8, 2025 | Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could a... |
| CVE-2025-30102 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low pri... |
| CVE-2025-30101 | MEDIUM | 6.3 | 0.1% | May 8, 2025 | Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now