2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53681 | HIGH | 7.2 | 0.4% | May 12, 2026 | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab... |
| CVE-2025-53680 | MEDIUM | 6.7 | 0.6% | May 12, 2026 | An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul... |
| CVE-2025-46311 | HIGH | 7.5 | 0.2% | May 12, 2026 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and... |
| CVE-2025-43524 | HIGH | 8.8 | 0.1% | May 12, 2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S... |
| CVE-2025-65719 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user... |
| CVE-2025-36515 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may... |
| CVE-2025-36510 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver... |
| CVE-2025-35991 | MEDIUM | 5.6 | 0.1% | May 12, 2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat... |
| CVE-2025-35990 | HIGH | 8.8 | 0.2% | May 12, 2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ... |
| CVE-2025-35979 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio... |
| CVE-2025-35969 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3... |
| CVE-2025-27723 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke... |
| CVE-2025-70842 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The f... |
| CVE-2025-12659 | HIGH | 7.8 | 0.2% | May 12, 2026 | Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could... |
| CVE-2025-6577 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So... |
| CVE-2025-40949 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-40948 | MEDIUM | 6.8 | 0.3% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-40947 | HIGH | 7.7 | 0.4% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-40946 | HIGH | 8.3 | 0.2% | May 12, 2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.... |
| CVE-2025-40833 | HIGH | 8.7 | 0.3% | May 12, 2026 | The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ... |
| CVE-2025-65418 | HIGH | 7.5 | 0.6% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary... |
| CVE-2025-65417 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page... |
| CVE-2025-65416 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. |
| CVE-2025-65415 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic... |
| CVE-2025-63750 | — | — | — | May 11, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now