2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48749 | CRITICAL | 9.1 | 0.4% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Info... |
| CVE-2025-48929 | CRITICAL | 9.8 | 0.3% | May 28, 2025 | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token ... |
| CVE-2025-45343 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of ... |
| CVE-2025-3357 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code du... |
| CVE-2025-5277 | CRITICAL | 9.6 | 1.3% | May 28, 2025 | aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M... |
| CVE-2025-5298 | CRITICAL | 9.8 | 0.8% | May 28, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte... |
| CVE-2025-5295 | CRITICAL | 9.8 | 0.6% | May 28, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code ... |
| CVE-2025-27528 | CRITICAL | 9.1 | 0.6% | May 28, 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through... |
| CVE-2025-4009 | CRITICAL | 9.3 | 74.9% | May 28, 2025 | The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w... |
| CVE-2025-32440 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the aut... |
| CVE-2025-5252 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability af... |
| CVE-2025-5251 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unk... |
| CVE-2025-5250 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is so... |
| CVE-2025-5249 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulner... |
| CVE-2025-48057 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and gener... |
| CVE-2025-5248 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affect... |
| CVE-2025-5246 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability ... |
| CVE-2025-41652 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated r... |
| CVE-2025-41651 | CRITICAL | 9.8 | 0.5% | May 27, 2025 | Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbit... |
| CVE-2025-2407 | CRITICAL | 9.3 | 0.4% | May 27, 2025 | Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted acc... |
| CVE-2025-5231 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability... |
| CVE-2025-5230 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unkn... |
| CVE-2025-5229 | CRITICAL | 9.8 | 0.4% | May 27, 2025 | A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by... |
| CVE-2025-48827 | CRITICAL | 9.8 | 69.6% | May 27, 2025 | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' ... |
| CVE-2025-48742 | CRITICAL | 9.8 | 0.3% | May 27, 2025 | The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now