2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5358 | CRITICAL | 9.8 | 0.4% | May 30, 2025 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec... |
| CVE-2025-5357 | CRITICAL | 9.8 | 0.6% | May 30, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability ... |
| CVE-2025-5356 | CRITICAL | 9.8 | 0.6% | May 30, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi... |
| CVE-2025-2500 | CRITICAL | 9.1 | 0.3% | May 30, 2025 | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an... |
| CVE-2025-48865 | CRITICAL | 9.1 | 0.5% | May 30, 2025 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl... |
| CVE-2025-48481 | CRITICAL | 9.8 | 0.5% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated ... |
| CVE-2025-47952 | CRITICAL | 9.1 | 0.8% | May 30, 2025 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a... |
| CVE-2025-48757 | CRITICAL | 9.3 | 0.7% | May 30, 2025 | An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers... |
| CVE-2025-44619 | CRITICAL | 9.1 | 0.3% | May 30, 2025 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attacker... |
| CVE-2025-46352 | CRITICAL | 9.8 | 0.7% | May 30, 2025 | The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string i... |
| CVE-2025-41438 | CRITICAL | 9.8 | 0.7% | May 30, 2025 | The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to ch... |
| CVE-2025-1907 | CRITICAL | 9.8 | 0.8% | May 30, 2025 | Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co... |
| CVE-2025-5332 | CRITICAL | 9.8 | 0.5% | May 29, 2025 | A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u... |
| CVE-2025-5331 | CRITICAL | 9.8 | 0.6% | May 29, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown ... |
| CVE-2025-5330 | CRITICAL | 9.8 | 0.6% | May 29, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o... |
| CVE-2025-31263 | CRITICAL | 9.1 | 0.3% | May 29, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to ... |
| CVE-2025-30466 | CRITICAL | 9.8 | 0.3% | May 29, 2025 | This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4... |
| CVE-2025-5325 | CRITICAL | 9.8 | 0.4% | May 29, 2025 | A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified ... |
| CVE-2025-4967 | CRITICAL | 9.1 | 0.4% | May 29, 2025 | Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections. |
| CVE-2025-48336 | CRITICAL | 9.8 | 0.4% | May 29, 2025 | Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This ... |
| CVE-2025-48471 | CRITICAL | 9.8 | 1.0% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o... |
| CVE-2025-5321 | CRITICAL | 9.9 | 0.5% | May 29, 2025 | A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R... |
| CVE-2025-48748 | CRITICAL | 10 | 0.3% | May 29, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. |
| CVE-2025-48047 | CRITICAL | 9.4 | 11.7% | May 29, 2025 | An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ... |
| CVE-2025-27151 | CRITICAL | 9.8 | 0.8% | May 29, 2025 | Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now