2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46633 | HIGH | 8.2 | 0.2% | May 1, 2025 | Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an ... |
| CVE-2025-46632 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to ... |
| CVE-2025-46631 | MEDIUM | 6.5 | 4.9% | May 1, 2025 | Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ... |
| CVE-2025-46630 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ... |
| CVE-2025-46629 | MEDIUM | 6.5 | 1.0% | May 1, 2025 | Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote... |
| CVE-2025-46628 | HIGH | 7.3 | 1.7% | May 1, 2025 | Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unautho... |
| CVE-2025-46627 | HIGH | 8.2 | 0.4% | May 1, 2025 | Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telne... |
| CVE-2025-46626 | HIGH | 7.3 | 0.2% | May 1, 2025 | Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda R... |
| CVE-2025-46625 | HIGH | 8.8 | 0.8% | May 1, 2025 | Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a... |
| CVE-2025-46569 | HIGH | 7.4 | 0.4% | May 1, 2025 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, ... |
| CVE-2025-29763 | — | — | — | May 1, 2025 | Rejected reason: “This CVE ID is Rejected and will not be used. The issue was determined to not be a vulnerability.” |
| CVE-2025-4174 | CRITICAL | 9.8 | 0.5% | May 1, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A... |
| CVE-2025-3517 | MEDIUM | 6.3 | 0.3% | May 1, 2025 | Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM us... |
| CVE-2025-36558 | MEDIUM | 6.1 | 13.3% | May 1, 2025 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for aut... |
| CVE-2025-36521 | HIGH | 8.8 | 0.4% | May 1, 2025 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption wi... |
| CVE-2025-35996 | CRITICAL | 9 | 11.2% | May 1, 2025 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename... |
| CVE-2025-35975 | HIGH | 8.8 | 0.5% | May 1, 2025 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. T... |
| CVE-2025-32011 | CRITICAL | 9.8 | 21.8% | May 1, 2025 | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can byp... |
| CVE-2025-24522 | CRITICAL | 10 | 0.7% | May 1, 2025 | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-... |
| CVE-2025-46568 | HIGH | 7.5 | 0.4% | May 1, 2025 | Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to ve... |
| CVE-2025-46567 | HIGH | 7.8 | 0.2% | May 1, 2025 | LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in t... |
| CVE-2025-46566 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE... |
| CVE-2025-46565 | MEDIUM | 5.3 | 1.1% | May 1, 2025 | Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the cont... |
| CVE-2025-46345 | MEDIUM | 6.9 | 0.3% | May 1, 2025 | Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t... |
| CVE-2025-46337 | CRITICAL | 10 | 0.6% | May 1, 2025 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now