2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46826 | LOW | 1.3 | 0.4% | May 7, 2025 | insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's ... |
| CVE-2025-46821 | MEDIUM | 5.3 | 0.2% | May 7, 2025 | Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI tem... |
| CVE-2025-46265 | HIGH | 8.8 | 0.3% | May 7, 2025 | On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may b... |
| CVE-2025-43878 | HIGH | 8.3 | 0.1% | May 7, 2025 | When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may ... |
| CVE-2025-41433 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is conf... |
| CVE-2025-41431 | HIGH | 8.7 | 0.4% | May 7, 2025 | When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Micro... |
| CVE-2025-41414 | HIGH | 8.7 | 0.4% | May 7, 2025 | When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate... |
| CVE-2025-41399 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can c... |
| CVE-2025-36557 | HIGH | 8.7 | 0.4% | May 7, 2025 | When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can ... |
| CVE-2025-36546 | CRITICAL | 9.2 | 0.4% | May 7, 2025 | On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication... |
| CVE-2025-36525 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to termin... |
| CVE-2025-36504 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase i... |
| CVE-2025-35995 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the url... |
| CVE-2025-31644 | HIGH | 8.7 | 26.1% | May 7, 2025 | When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS... |
| CVE-2025-4043 | MEDIUM | 6.8 | 0.3% | May 7, 2025 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system ... |
| CVE-2025-3925 | HIGH | 8.5 | 0.2% | May 7, 2025 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution... |
| CVE-2025-31177 | MEDIUM | 5.5 | 0.2% | May 7, 2025 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. |
| CVE-2025-45514 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm. |
| CVE-2025-45388 | MEDIUM | 6.1 | 0.3% | May 7, 2025 | Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers c... |
| CVE-2025-3476 | CRITICAL | 9.4 | 0.3% | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege e... |
| CVE-2025-3272 | MEDIUM | 6.7 | 0.2% | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authentica... |
| CVE-2025-30147 | HIGH | 8.7 | 0.2% | May 7, 2025 | Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum cli... |
| CVE-2025-29746 | MEDIUM | 6.1 | 0.2% | May 7, 2025 | Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the colle... |
| CVE-2025-26169 | HIGH | 8.1 | 0.2% | May 7, 2025 | IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from... |
| CVE-2025-26168 | HIGH | 8.1 | 0.2% | May 7, 2025 | IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code executio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now