2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4660 | CRITICAL | 9.8 | 1.0% | May 13, 2025 | A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access co... |
| CVE-2025-4658 | CRITICAL | 9.8 | 0.3% | May 13, 2025 | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by... |
| CVE-2025-3757 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by... |
| CVE-2025-30387 | CRITICAL | 9.8 | 1.1% | May 13, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker ... |
| CVE-2025-45858 | CRITICAL | 9.8 | 9.1% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f... |
| CVE-2025-45857 | CRITICAL | 9.8 | 0.9% | May 13, 2025 | EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in... |
| CVE-2025-31493 | CRITICAL | 9.1 | 0.5% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-28056 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component. |
| CVE-2025-22462 | CRITICAL | 9.8 | 1.9% | May 13, 2025 | An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se... |
| CVE-2025-44831 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface. |
| CVE-2025-32756 | CRITICAL | 9.8 | 31.4% | May 13, 2025 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa... |
| CVE-2025-30159 | CRITICAL | 9.1 | 0.6% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-40628 | CRITICAL | 9.3 | 0.3% | May 13, 2025 | SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update an... |
| CVE-2025-40566 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve... |
| CVE-2025-33025 | CRITICAL | 9.9 | 1.2% | May 13, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-33024 | CRITICAL | 9.9 | 1.2% | May 13, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-32469 | CRITICAL | 9.9 | 1.2% | May 13, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-26390 | CRITICAL | 9.8 | 0.6% | May 13, 2025 | A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of af... |
| CVE-2025-26389 | CRITICAL | 9.8 | 0.8% | May 13, 2025 | A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in af... |
| CVE-2025-4632 | CRITICAL | 9.8 | 24.0% | May 13, 2025 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2... |
| CVE-2025-42999 | CRITICAL | 9.1 | 11.3% | May 13, 2025 | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious c... |
| CVE-2025-30012 | CRITICAL | 9.8 | 0.7% | May 13, 2025 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which al... |
| CVE-2025-30448 | CRITICAL | 9.1 | 0.9% | May 12, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.... |
| CVE-2025-30436 | CRITICAL | 9.1 | 0.4% | May 12, 2025 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 1... |
| CVE-2025-3659 | CRITICAL | 9.4 | 0.3% | May 12, 2025 | Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now