2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20190 | MEDIUM | 6.5 | 0.4% | May 7, 2025 | A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authen... |
| CVE-2025-20189 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Ser... |
| CVE-2025-20188 | CRITICAL | 10 | 17.9% | May 7, 2025 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de... |
| CVE-2025-20187 | MEDIUM | 6.5 | 1.2% | May 7, 2025 | A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could... |
| CVE-2025-20186 | HIGH | 8.8 | 1.2% | May 7, 2025 | A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software co... |
| CVE-2025-20182 | HIGH | 8.6 | 0.5% | May 7, 2025 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance ... |
| CVE-2025-20181 | MEDIUM | 6.8 | 0.2% | May 7, 2025 | A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow a... |
| CVE-2025-20164 | HIGH | 8.3 | 0.3% | May 7, 2025 | A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authent... |
| CVE-2025-20162 | HIGH | 8.6 | 0.4% | May 7, 2025 | A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote at... |
| CVE-2025-20157 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, co... |
| CVE-2025-20155 | MEDIUM | 6 | 0.1% | May 7, 2025 | A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write ... |
| CVE-2025-20154 | HIGH | 8.6 | 0.4% | May 7, 2025 | A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE... |
| CVE-2025-20151 | MEDIUM | 4.3 | 0.3% | May 7, 2025 | A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS ... |
| CVE-2025-20147 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2025-20140 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLC... |
| CVE-2025-20137 | MEDIUM | 4.7 | 0.2% | May 7, 2025 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 100... |
| CVE-2025-20122 | HIGH | 7.8 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated... |
| CVE-2025-46551 | LOW | 3.7 | 0.2% | May 7, 2025 | JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio... |
| CVE-2025-46827 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtai... |
| CVE-2025-47692 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configure... |
| CVE-2025-47691 | MEDIUM | 5.5 | 0.2% | May 7, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-memb... |
| CVE-2025-47688 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec... |
| CVE-2025-47686 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SE... |
| CVE-2025-47685 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS.... |
| CVE-2025-47684 | MEDIUM | 5.4 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP smaily-for-wp allows Cross Site Request Forgery.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now