2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45790 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /li... |
| CVE-2025-45789 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules. |
| CVE-2025-45788 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules. |
| CVE-2025-45787 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules. |
| CVE-2025-0505 | CRITICAL | 10 | 0.6% | May 8, 2025 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain ... |
| CVE-2025-26845 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can us... |
| CVE-2025-45841 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter... |
| CVE-2025-26844 | CRITICAL | 9.8 | 0.4% | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. |
| CVE-2025-36546 | CRITICAL | 9.2 | 0.4% | May 7, 2025 | On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication... |
| CVE-2025-3476 | CRITICAL | 9.4 | 0.3% | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege e... |
| CVE-2025-46828 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve... |
| CVE-2025-20221 | CRITICAL | 9.1 | 0.4% | May 7, 2025 | A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote ... |
| CVE-2025-20188 | CRITICAL | 10 | 17.9% | May 7, 2025 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de... |
| CVE-2025-47688 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec... |
| CVE-2025-47657 | CRITICAL | 9.3 | 0.3% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds P... |
| CVE-2025-47635 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Req... |
| CVE-2025-47548 | CRITICAL | 9.8 | 0.2% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress act... |
| CVE-2025-2777 | CRITICAL | 9.8 | 79.1% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the l... |
| CVE-2025-2776 | CRITICAL | 9.8 | 73.0% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S... |
| CVE-2025-4104 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t... |
| CVE-2025-20968 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20967 | CRITICAL | 9.1 | 0.2% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20949 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary ... |
| CVE-2025-0668 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-32404 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now