2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23165 | LOW | 3.7 | 0.5% | May 19, 2025 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path... |
| CVE-2025-48219 | LOW | 3.5 | 0.3% | May 18, 2025 | O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multim... |
| CVE-2025-4852 | LOW | 3.4 | 0.3% | May 18, 2025 | A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue... |
| CVE-2025-4819 | LOW | 3.1 | 0.4% | May 17, 2025 | A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of th... |
| CVE-2025-22233 | LOW | 3.1 | 0.4% | May 16, 2025 | CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and fo... |
| CVE-2025-47929 | LOW | 2.1 | 0.3% | May 15, 2025 | DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scr... |
| CVE-2025-47774 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t... |
| CVE-2025-47285 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `... |
| CVE-2025-47279 | LOW | 3.1 | 0.3% | May 15, 2025 | Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i... |
| CVE-2025-2570 | LOW | 2.7 | 0.3% | May 15, 2025 | Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have... |
| CVE-2025-4762 | LOW | 2 | 0.3% | May 15, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.... |
| CVE-2025-27525 | LOW | 3.9 | 0.1% | May 15, 2025 | Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a... |
| CVE-2025-32421 | LOW | 3.7 | 0.7% | May 14, 2025 | Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-... |
| CVE-2025-0138 | LOW | 2 | 0.3% | May 14, 2025 | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet... |
| CVE-2025-0135 | LOW | 3.3 | 0.1% | May 14, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0133 | LOW | 2.7 | 43.5% | May 14, 2025 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw... |
| CVE-2025-20030 | LOW | 2.6 | 0.2% | May 13, 2025 | Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge ... |
| CVE-2025-47278 | LOW | 1.8 | 0.2% | May 13, 2025 | Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura... |
| CVE-2025-40571 | LOW | 2.2 | 0.2% | May 13, 2025 | A vulnerability has been identified in Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SS... |
| CVE-2025-46748 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated user attempting to change their password could do so without using the current password. |
| CVE-2025-46744 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated administrator could modify the Created By username for a user account |
| CVE-2025-47274 | LOW | 2.4 | 0.1% | May 12, 2025 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to... |
| CVE-2025-46718 | LOW | 3.3 | 0.2% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ... |
| CVE-2025-46717 | LOW | 3.3 | 0.3% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l... |
| CVE-2025-46729 | LOW | 2.1 | 0.4% | May 12, 2025 | julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now