2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4452 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability was found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this issue is the function ... |
| CVE-2025-4451 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability has been found in D-Link DIR-619L 2.04B04 and classified as critical. Affected by this vulnerability is ... |
| CVE-2025-4450 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.04B04. Affected is the function formSe... |
| CVE-2025-4449 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.04B04. This issue affects the fun... |
| CVE-2025-4448 | CRITICAL | 9.8 | 2.3% | May 9, 2025 | A vulnerability classified as critical was found in D-Link DIR-619L 2.04B04. This vulnerability affects the function for... |
| CVE-2025-4445 | CRITICAL | 9.8 | 6.5% | May 9, 2025 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. ... |
| CVE-2025-4443 | CRITICAL | 9.8 | 53.8% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub... |
| CVE-2025-4442 | CRITICAL | 9.8 | 2.1% | May 9, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-4441 | CRITICAL | 9.8 | 2.1% | May 8, 2025 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form... |
| CVE-2025-47732 | CRITICAL | 9.8 | 2.9% | May 8, 2025 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. |
| CVE-2025-29972 | CRITICAL | 9.8 | 2.6% | May 8, 2025 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing ... |
| CVE-2025-29813 | CRITICAL | 9.8 | 1.5% | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov... |
| CVE-2025-27720 | CRITICAL | 9.3 | 0.2% | May 8, 2025 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal ... |
| CVE-2025-45798 | CRITICAL | 9.8 | 1.0% | May 8, 2025 | A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in... |
| CVE-2025-45797 | CRITICAL | 9.8 | 11.8% | May 8, 2025 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the impr... |
| CVE-2025-45790 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /li... |
| CVE-2025-45789 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules. |
| CVE-2025-45788 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules. |
| CVE-2025-45787 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules. |
| CVE-2025-0505 | CRITICAL | 10 | 0.6% | May 8, 2025 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain ... |
| CVE-2025-26845 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can us... |
| CVE-2025-45841 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter... |
| CVE-2025-26844 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. |
| CVE-2025-36546 | CRITICAL | 9.2 | 0.4% | May 7, 2025 | On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication... |
| CVE-2025-3476 | CRITICAL | 9.4 | 0.3% | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now