2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5052 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-5051 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th... |
| CVE-2025-46412 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authenticati... |
| CVE-2025-41426 | CRITICAL | 9.8 | 0.7% | May 21, 2025 | Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerabili... |
| CVE-2025-36535 | CRITICAL | 10 | 1.0% | May 21, 2025 | The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead t... |
| CVE-2025-5050 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown pr... |
| CVE-2025-5049 | CRITICAL | 9.8 | 0.6% | May 21, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unkn... |
| CVE-2025-44083 | CRITICAL | 9.8 | 0.8% | May 21, 2025 | An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication |
| CVE-2025-27558 | CRITICAL | 9.1 | 0.3% | May 21, 2025 | IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Ac... |
| CVE-2025-5032 | CRITICAL | 9.8 | 0.4% | May 21, 2025 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu... |
| CVE-2025-20242 | CRITICAL | 9.1 | 2.3% | May 21, 2025 | A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthent... |
| CVE-2025-48200 | CRITICAL | 10 | 0.6% | May 21, 2025 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution. |
| CVE-2025-41232 | CRITICAL | 9.1 | 0.5% | May 21, 2025 | Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an autho... |
| CVE-2025-4524 | CRITICAL | 9.8 | 9.1% | May 21, 2025 | The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-4094 | CRITICAL | 9.8 | 16.4% | May 21, 2025 | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation ... |
| CVE-2025-5008 | CRITICAL | 9.8 | 0.4% | May 20, 2025 | A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by t... |
| CVE-2025-5006 | CRITICAL | 9.8 | 0.4% | May 20, 2025 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an un... |
| CVE-2025-5004 | CRITICAL | 9.8 | 0.4% | May 20, 2025 | A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affect... |
| CVE-2025-5003 | CRITICAL | 9.8 | 0.4% | May 20, 2025 | A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnera... |
| CVE-2025-5002 | CRITICAL | 9.8 | 0.4% | May 20, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th... |
| CVE-2025-5000 | CRITICAL | 9.8 | 10.5% | May 20, 2025 | A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. ... |
| CVE-2025-4999 | CRITICAL | 9.8 | 11.3% | May 20, 2025 | A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected ... |
| CVE-2025-44898 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_logi... |
| CVE-2025-44897 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_up... |
| CVE-2025-44896 | CRITICAL | 9.8 | 0.5% | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now