2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1948 | HIGH | 7.5 | 0.6% | May 8, 2025 | In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 set... |
| CVE-2025-44021 | LOW | 2.8 | 0.1% | May 8, 2025 | OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w... |
| CVE-2025-26847 | HIGH | 7.5 | 0.3% | May 8, 2025 | An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked. |
| CVE-2025-26845 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can us... |
| CVE-2025-4132 | — | — | — | May 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-45847 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the ... |
| CVE-2025-45846 | HIGH | 8.8 | 0.5% | May 8, 2025 | ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in th... |
| CVE-2025-45845 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet... |
| CVE-2025-45844 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter... |
| CVE-2025-45843 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter... |
| CVE-2025-45842 | HIGH | 8.8 | 0.8% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet... |
| CVE-2025-45841 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter... |
| CVE-2025-43926 | MEDIUM | 6.1 | 0.2% | May 8, 2025 | An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateA... |
| CVE-2025-26844 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. |
| CVE-2025-26842 | HIGH | 7.5 | 0.3% | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-ma... |
| CVE-2025-4207 | MEDIUM | 5.9 | 0.6% | May 8, 2025 | Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial ... |
| CVE-2025-45820 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/p... |
| CVE-2025-45819 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/au... |
| CVE-2025-45818 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/it... |
| CVE-2025-47730 | HIGH | 7.5 | 0.3% | May 8, 2025 | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM ... |
| CVE-2025-47729 | MEDIUM | 4.9 | 0.4% | May 8, 2025 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal... |
| CVE-2025-4208 | MEDIUM | 6.3 | 0.3% | May 8, 2025 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code E... |
| CVE-2025-3862 | MEDIUM | 5.4 | 0.2% | May 8, 2025 | Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
| CVE-2025-3506 | MEDIUM | 5.3 | 0.3% | May 8, 2025 | Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 an... |
| CVE-2025-3468 | MEDIUM | 5.4 | 0.2% | May 8, 2025 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now