2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32002 | CRITICAL | 9.8 | 1.7% | May 15, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA netw... |
| CVE-2025-3917 | CRITICAL | 9.8 | 0.7% | May 15, 2025 | The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v... |
| CVE-2025-47889 | CRITICAL | 9.8 | 0.6% | May 14, 2025 | In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" ... |
| CVE-2025-47884 | CRITICAL | 9.1 | 0.6% | May 14, 2025 | In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentiall... |
| CVE-2025-27891 | CRITICAL | 9.1 | 0.4% | May 14, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-32363 | CRITICAL | 9.8 | 0.8% | May 14, 2025 | mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization... |
| CVE-2025-4641 | CRITICAL | 9.3 | 0.5% | May 14, 2025 | Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W... |
| CVE-2025-4638 | CRITICAL | 9.8 | 0.4% | May 14, 2025 | A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (P... |
| CVE-2025-47781 | CRITICAL | 9.8 | 0.5% | May 14, 2025 | Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application featu... |
| CVE-2025-47777 | CRITICAL | 9.6 | 0.8% | May 14, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to ... |
| CVE-2025-47436 | CRITICAL | 9.8 | 0.5% | May 14, 2025 | Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompre... |
| CVE-2025-47445 | CRITICAL | 9.8 | 4.7% | May 14, 2025 | Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev... |
| CVE-2025-47292 | CRITICAL | 9.5 | 0.6% | May 14, 2025 | Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175b... |
| CVE-2025-3623 | CRITICAL | 9.1 | 0.8% | May 14, 2025 | The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6... |
| CVE-2025-43567 | CRITICAL | 9.3 | 0.4% | May 13, 2025 | Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could ... |
| CVE-2025-43564 | CRITICAL | 9.1 | 9.3% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-43563 | CRITICAL | 9.1 | 9.3% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-43562 | CRITICAL | 9.1 | 33.2% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements ... |
| CVE-2025-43561 | CRITICAL | 9.1 | 12.6% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c... |
| CVE-2025-43560 | CRITICAL | 9.1 | 11.5% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-43559 | CRITICAL | 9.1 | 1.2% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-45863 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMa... |
| CVE-2025-45865 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formD... |
| CVE-2025-45861 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the fo... |
| CVE-2025-45746 | CRITICAL | 9.8 | 0.3% | May 13, 2025 | In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authentica... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now