2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46570 | LOW | 2.6 | 0.2% | May 29, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is p... |
| CVE-2025-3913 | LOW | 3.8 | 0.3% | May 29, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate pe... |
| CVE-2025-27706 | LOW | 3.4 | 0.2% | May 28, 2025 | CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to ver... |
| CVE-2025-3864 | LOW | 2.3 | 0.7% | May 28, 2025 | Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote a... |
| CVE-2025-47295 | LOW | 3.7 | 0.6% | May 28, 2025 | A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 th... |
| CVE-2025-46777 | LOW | 2.7 | 0.2% | May 28, 2025 | A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,... |
| CVE-2025-24473 | LOW | 3.7 | 0.4% | May 28, 2025 | A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindow... |
| CVE-2025-2826 | LOW | 2.6 | 0.5% | May 27, 2025 | n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 st... |
| CVE-2025-48370 | LOW | 2.7 | 0.7% | May 27, 2025 | auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI... |
| CVE-2025-2236 | LOW | 2.1 | 0.2% | May 27, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica... |
| CVE-2025-46804 | LOW | 3.3 | 0.2% | May 26, 2025 | A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information... |
| CVE-2025-5179 | LOW | 3.4 | 0.3% | May 26, 2025 | A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by ... |
| CVE-2025-5138 | LOW | 3.5 | 0.4% | May 25, 2025 | A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability... |
| CVE-2025-48376 | LOW | 2.4 | 0.2% | May 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-48708 | LOW | 3.3 | 0.3% | May 23, 2025 | gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for ... |
| CVE-2025-48064 | LOW | 3.3 | 0.2% | May 21, 2025 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,... |
| CVE-2025-5031 | LOW | 3.1 | 0.4% | May 21, 2025 | A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some u... |
| CVE-2025-48009 | LOW | 3.1 | 0.2% | May 21, 2025 | Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single ... |
| CVE-2025-1421 | LOW | 2.4 | 0.2% | May 21, 2025 | Data provided in a request performed to the server while activating a new device are put in a database. Other high privi... |
| CVE-2025-1420 | LOW | 2.4 | 0.2% | May 21, 2025 | Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-p... |
| CVE-2025-1419 | LOW | 2.4 | 0.2% | May 21, 2025 | Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perfo... |
| CVE-2025-48015 | LOW | 3.7 | 0.2% | May 20, 2025 | Failed login response could be different depending on whether the username was local or central. |
| CVE-2025-47938 | LOW | 3.8 | 0.2% | May 20, 2025 | TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51... |
| CVE-2025-4945 | LOW | 3.7 | 0.5% | May 19, 2025 | A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software.... |
| CVE-2025-31185 | LOW | 3.3 | 0.2% | May 19, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now