2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47929 | LOW | 2.1 | 0.3% | May 15, 2025 | DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scr... |
| CVE-2025-47774 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t... |
| CVE-2025-47285 | LOW | 2.9 | 0.4% | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `... |
| CVE-2025-47279 | LOW | 3.1 | 0.3% | May 15, 2025 | Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i... |
| CVE-2025-2570 | LOW | 2.7 | 0.3% | May 15, 2025 | Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have... |
| CVE-2025-4762 | LOW | 2 | 0.3% | May 15, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.... |
| CVE-2025-27525 | LOW | 3.9 | 0.1% | May 15, 2025 | Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a... |
| CVE-2025-32421 | LOW | 3.7 | 0.7% | May 14, 2025 | Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-... |
| CVE-2025-0138 | LOW | 2 | 0.3% | May 14, 2025 | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet... |
| CVE-2025-0135 | LOW | 3.3 | 0.1% | May 14, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0133 | LOW | 2.7 | 43.5% | May 14, 2025 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw... |
| CVE-2025-20030 | LOW | 2.6 | 0.2% | May 13, 2025 | Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge ... |
| CVE-2025-47278 | LOW | 1.8 | 0.2% | May 13, 2025 | Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura... |
| CVE-2025-40571 | LOW | 2.2 | 0.2% | May 13, 2025 | A vulnerability has been identified in Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SS... |
| CVE-2025-46748 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated user attempting to change their password could do so without using the current password. |
| CVE-2025-46744 | LOW | 2.7 | 0.2% | May 12, 2025 | An authenticated administrator could modify the Created By username for a user account |
| CVE-2025-47274 | LOW | 2.4 | 0.1% | May 12, 2025 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to... |
| CVE-2025-46718 | LOW | 3.3 | 0.2% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ... |
| CVE-2025-46717 | LOW | 3.3 | 0.3% | May 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l... |
| CVE-2025-46729 | LOW | 2.1 | 0.4% | May 12, 2025 | julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the... |
| CVE-2025-4537 | LOW | 3.1 | 0.2% | May 11, 2025 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue i... |
| CVE-2025-47736 | LOW | 2.9 | 0.2% | May 9, 2025 | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v... |
| CVE-2025-46812 | LOW | 2 | 0.6% | May 8, 2025 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to... |
| CVE-2025-46712 | LOW | 3.7 | 0.4% | May 8, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-... |
| CVE-2025-44021 | LOW | 2.8 | 0.1% | May 8, 2025 | OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now