2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13755 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) store... |
| CVE-2025-62745 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team S... |
| CVE-2025-46371 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ... |
| CVE-2025-32751 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low... |
| CVE-2025-32746 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un... |
| CVE-2025-32745 | MEDIUM | 6.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthentica... |
| CVE-2025-31985 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty... |
| CVE-2025-15369 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-15645 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t... |
| CVE-2025-57798 | MEDIUM | 5.5 | 0.2% | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1... |
| CVE-2025-40904 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an... |
| CVE-2025-40903 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid... |
| CVE-2025-40902 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p... |
| CVE-2025-40901 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation... |
| CVE-2025-40900 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-65954 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel... |
| CVE-2025-4202 | MEDIUM | 4.3 | 0.2% | May 16, 2026 | The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo... |
| CVE-2025-67031 | MEDIUM | 6.3 | 0.3% | May 15, 2026 | ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera... |
| CVE-2025-67437 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a... |
| CVE-2025-14972 | MEDIUM | 4.1 | 0.1% | May 15, 2026 | * Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually... |
| CVE-2025-66664 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf... |
| CVE-2025-54511 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp... |
| CVE-2025-48516 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc... |
| CVE-2025-48513 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini... |
| CVE-2025-29944 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now