2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47420 | HIGH | 8.7 | 0.3% | May 6, 2025 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.2153... |
| CVE-2025-0853 | HIGH | 7.5 | 0.3% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' ... |
| CVE-2025-47419 | CRITICAL | 10 | 0.2% | May 6, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ... |
| CVE-2025-47418 | MEDIUM | 5.3 | 0.3% | May 6, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi... |
| CVE-2025-46573 | HIGH | 8.6 | 0.3% | May 6, 2025 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ... |
| CVE-2025-46572 | CRITICAL | 9.3 | 0.4% | May 6, 2025 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ... |
| CVE-2025-44899 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we... |
| CVE-2025-44073 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. |
| CVE-2025-0649 | HIGH | 7.5 | 0.2% | May 6, 2025 | Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbound... |
| CVE-2025-47417 | MEDIUM | 5.1 | 0.4% | May 6, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi... |
| CVE-2025-47256 | MEDIUM | 5.6 | 0.2% | May 6, 2025 | Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha form... |
| CVE-2025-46820 | HIGH | 7.1 | 0.2% | May 6, 2025 | phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom wo... |
| CVE-2025-46816 | CRITICAL | 9.4 | 0.6% | May 6, 2025 | goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a... |
| CVE-2025-4388 | MEDIUM | 6.1 | 3.4% | May 6, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024... |
| CVE-2025-46815 | HIGH | 8 | 0.4% | May 6, 2025 | The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API... |
| CVE-2025-44900 | MEDIUM | 6.5 | 0.2% | May 6, 2025 | In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the m... |
| CVE-2025-37730 | MEDIUM | 6.5 | 0.1% | May 6, 2025 | Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod... |
| CVE-2025-25014 | CRITICAL | 9.8 | 13.7% | May 6, 2025 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea... |
| CVE-2025-4041 | CRITICAL | 9.3 | 0.6% | May 6, 2025 | In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh serve... |
| CVE-2025-46736 | MEDIUM | 5.3 | 0.3% | May 6, 2025 | Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal... |
| CVE-2025-46735 | LOW | 1.1 | 0.6% | May 6, 2025 | Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue ... |
| CVE-2025-45250 | MEDIUM | 5.5 | 0.2% | May 6, 2025 | MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/u... |
| CVE-2025-32022 | MEDIUM | 4.6 | 0.1% | May 6, 2025 | Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot whi... |
| CVE-2025-30165 | HIGH | 8 | 0.5% | May 6, 2025 | vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, ... |
| CVE-2025-26262 | MEDIUM | 6.5 | 0.3% | May 6, 2025 | An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now