2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32750 | HIGH | 7.5 | 0.4% | May 20, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit... |
| CVE-2025-11954 | HIGH | 8 | 0.2% | May 20, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S... |
| CVE-2025-31985 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty... |
| CVE-2025-31973 | CRITICAL | 9.8 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd... |
| CVE-2025-33255 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial... |
| CVE-2025-15369 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-15645 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t... |
| CVE-2025-57798 | MEDIUM | 5.5 | 0.2% | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1... |
| CVE-2025-61081 | — | — | — | May 19, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-70950 | HIGH | 7.3 | 0.5% | May 19, 2026 | An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request. |
| CVE-2025-51427 | HIGH | 7.3 | 0.5% | May 19, 2026 | An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t... |
| CVE-2025-40904 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an... |
| CVE-2025-40903 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid... |
| CVE-2025-40902 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p... |
| CVE-2025-40901 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation... |
| CVE-2025-40900 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-14575 | LOW | 1.8 | 0.1% | May 19, 2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (... |
| CVE-2025-15609 | HIGH | 7.5 | 0.4% | May 19, 2026 | The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow... |
| CVE-2025-65954 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel... |
| CVE-2025-57282 | HIGH | 8.8 | 1.0% | May 18, 2026 | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. |
| CVE-2025-56352 | HIGH | 7.5 | 0.3% | May 18, 2026 | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri... |
| CVE-2025-4202 | MEDIUM | 4.3 | 0.2% | May 16, 2026 | The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo... |
| CVE-2025-67031 | MEDIUM | 6.3 | 0.3% | May 15, 2026 | ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera... |
| CVE-2025-67437 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a... |
| CVE-2025-14972 | MEDIUM | 4.1 | 0.1% | May 15, 2026 | * Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now