2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1907 | CRITICAL | 9.8 | 0.8% | May 30, 2025 | Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co... |
| CVE-2025-5332 | CRITICAL | 9.8 | 0.5% | May 29, 2025 | A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u... |
| CVE-2025-5331 | CRITICAL | 9.8 | 0.7% | May 29, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown ... |
| CVE-2025-5330 | CRITICAL | 9.8 | 0.6% | May 29, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o... |
| CVE-2025-31263 | CRITICAL | 9.1 | 0.3% | May 29, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to ... |
| CVE-2025-30466 | CRITICAL | 9.8 | 0.3% | May 29, 2025 | This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4... |
| CVE-2025-5325 | CRITICAL | 9.8 | 0.4% | May 29, 2025 | A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified ... |
| CVE-2025-4967 | CRITICAL | 9.1 | 0.4% | May 29, 2025 | Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections. |
| CVE-2025-48336 | CRITICAL | 9.8 | 0.4% | May 29, 2025 | Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This ... |
| CVE-2025-48471 | CRITICAL | 9.8 | 1.0% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o... |
| CVE-2025-5321 | CRITICAL | 9.9 | 0.5% | May 29, 2025 | A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R... |
| CVE-2025-48748 | CRITICAL | 10 | 0.3% | May 29, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. |
| CVE-2025-48047 | CRITICAL | 9.4 | 11.7% | May 29, 2025 | An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ... |
| CVE-2025-27151 | CRITICAL | 9.8 | 0.8% | May 29, 2025 | Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st... |
| CVE-2025-3755 | CRITICAL | 9.1 | 0.7% | May 29, 2025 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation ME... |
| CVE-2025-48749 | CRITICAL | 9.1 | 0.4% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Info... |
| CVE-2025-48929 | CRITICAL | 9.8 | 0.3% | May 28, 2025 | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token ... |
| CVE-2025-45343 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of ... |
| CVE-2025-3357 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code du... |
| CVE-2025-5277 | CRITICAL | 9.6 | 1.3% | May 28, 2025 | aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M... |
| CVE-2025-5298 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte... |
| CVE-2025-5295 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code ... |
| CVE-2025-27528 | CRITICAL | 9.1 | 0.6% | May 28, 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through... |
| CVE-2025-4009 | CRITICAL | 9.3 | 74.9% | May 28, 2025 | The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w... |
| CVE-2025-32440 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now