2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43564 | CRITICAL | 9.1 | 9.3% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-43563 | CRITICAL | 9.1 | 9.3% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-43562 | CRITICAL | 9.1 | 33.2% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements ... |
| CVE-2025-43561 | CRITICAL | 9.1 | 12.6% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c... |
| CVE-2025-43560 | CRITICAL | 9.1 | 11.5% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-43559 | CRITICAL | 9.1 | 1.2% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-45863 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMa... |
| CVE-2025-45865 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formD... |
| CVE-2025-45861 | CRITICAL | 9.8 | 0.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the fo... |
| CVE-2025-45746 | CRITICAL | 9.8 | 0.3% | May 13, 2025 | In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authentica... |
| CVE-2025-4660 | CRITICAL | 9.8 | 1.0% | May 13, 2025 | A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access co... |
| CVE-2025-4658 | CRITICAL | 9.8 | 0.3% | May 13, 2025 | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by... |
| CVE-2025-3757 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by... |
| CVE-2025-30387 | CRITICAL | 9.8 | 1.1% | May 13, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker ... |
| CVE-2025-45858 | CRITICAL | 9.8 | 9.1% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f... |
| CVE-2025-45857 | CRITICAL | 9.8 | 0.9% | May 13, 2025 | EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in... |
| CVE-2025-31493 | CRITICAL | 9.1 | 0.5% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-28056 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component. |
| CVE-2025-22462 | CRITICAL | 9.8 | 1.9% | May 13, 2025 | An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se... |
| CVE-2025-44831 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface. |
| CVE-2025-32756 | CRITICAL | 9.8 | 31.4% | May 13, 2025 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa... |
| CVE-2025-30159 | CRITICAL | 9.1 | 0.6% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-40628 | CRITICAL | 9.3 | 0.3% | May 13, 2025 | SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update an... |
| CVE-2025-40566 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve... |
| CVE-2025-33025 | CRITICAL | 9.9 | 1.2% | May 13, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now