2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47735 | CRITICAL | 9.8 | 0.3% | May 9, 2025 | inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization. |
| CVE-2025-4457 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerabilit... |
| CVE-2025-4456 | CRITICAL | 9.8 | 0.8% | May 9, 2025 | A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown f... |
| CVE-2025-3714 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-3711 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-3710 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.2... |
| CVE-2025-4454 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4453 | CRITICAL | 9.8 | 7.6% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function form... |
| CVE-2025-3811 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2025-3810 | CRITICAL | 9.8 | 0.6% | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2025-4452 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this issue is the function ... |
| CVE-2025-4451 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is ... |
| CVE-2025-4450 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.04B04. Affected is the function formSe... |
| CVE-2025-4449 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.04B04. This issue affects the fun... |
| CVE-2025-4448 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability classified as critical was found in D-Link DIR-619L 2.04B04. This vulnerability affects the function for... |
| CVE-2025-4445 | CRITICAL | 9.8 | 6.5% | May 9, 2025 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. ... |
| CVE-2025-4443 | CRITICAL | 9.8 | 53.8% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub... |
| CVE-2025-4442 | CRITICAL | 9.8 | 2.1% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4441 | CRITICAL | 9.8 | 2.1% | May 8, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form... |
| CVE-2025-47732 | CRITICAL | 9.8 | 2.9% | May 8, 2025 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. |
| CVE-2025-29972 | CRITICAL | 9.8 | 2.6% | May 8, 2025 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing ... |
| CVE-2025-29813 | CRITICAL | 9.8 | 1.5% | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov... |
| CVE-2025-27720 | CRITICAL | 9.3 | 0.2% | May 8, 2025 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal ... |
| CVE-2025-45798 | CRITICAL | 9.8 | 1.0% | May 8, 2025 | A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in... |
| CVE-2025-45797 | CRITICAL | 9.8 | 11.8% | May 8, 2025 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the impr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now