2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41271 | HIGH | 7.5 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hos... |
| CVE-2025-41267 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41266 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41265 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-11262 | HIGH | 7.2 | 0.2% | May 29, 2026 | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all... |
| CVE-2025-11993 | HIGH | 8.8 | 0.4% | May 29, 2026 | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve... |
| CVE-2025-69600 | HIGH | 7.8 | 0.8% | May 27, 2026 | Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut... |
| CVE-2025-70103 | HIGH | 7.3 | 0.4% | May 27, 2026 | Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function i... |
| CVE-2025-71306 | HIGH | 7.1 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: ima: Fix stack-out-of-bounds in is_bprm_creds_for_e... |
| CVE-2025-3633 | HIGH | 8.2 | 0.3% | May 27, 2026 | IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable... |
| CVE-2025-52747 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox -... |
| CVE-2025-30028 | HIGH | 8.6 | 0.4% | May 27, 2026 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. |
| CVE-2025-22741 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Fr... |
| CVE-2025-14713 | HIGH | 7.5 | 0.5% | May 27, 2026 | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0... |
| CVE-2025-41670 | HIGH | 8.7 | 0.2% | May 27, 2026 | A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co... |
| CVE-2025-41669 | HIGH | 8.8 | 0.2% | May 27, 2026 | The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade... |
| CVE-2025-46284 | HIGH | 7 | 0.1% | May 26, 2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An... |
| CVE-2025-43306 | HIGH | 7.8 | 0.1% | May 26, 2026 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta... |
| CVE-2025-14361 | HIGH | 7.1 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly... |
| CVE-2025-36221 | HIGH | 7.5 | 0.3% | May 26, 2026 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default pas... |
| CVE-2025-36126 | HIGH | 7.6 | 0.2% | May 26, 2026 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to store... |
| CVE-2025-11482 | HIGH | 8.7 | 0.3% | May 26, 2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating Syst... |
| CVE-2025-45145 | HIGH | 7.5 | 0.7% | May 22, 2026 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attac... |
| CVE-2025-32749 | HIGH | 7.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit... |
| CVE-2025-32747 | HIGH | 7.8 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now