2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71214 | HIGH | 7.8 | 0.4% | May 21, 2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac... |
| CVE-2025-71213 | HIGH | 7.8 | 0.3% | May 21, 2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ... |
| CVE-2025-71212 | HIGH | 7.8 | 0.5% | May 21, 2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg... |
| CVE-2025-71211 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-71210 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-13479 | HIGH | 7.5 | 0.3% | May 21, 2026 | Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu ... |
| CVE-2025-13477 | HIGH | 7.1 | 0.2% | May 21, 2026 | Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in... |
| CVE-2025-32750 | HIGH | 7.5 | 0.4% | May 20, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit... |
| CVE-2025-11954 | HIGH | 8 | 0.2% | May 20, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S... |
| CVE-2025-31985 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty... |
| CVE-2025-31973 | CRITICAL | 9.8 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd... |
| CVE-2025-33255 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial... |
| CVE-2025-15369 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-15645 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t... |
| CVE-2025-57798 | MEDIUM | 5.5 | 0.2% | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1... |
| CVE-2025-61081 | — | — | — | May 19, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-70950 | HIGH | 7.3 | 0.5% | May 19, 2026 | An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request. |
| CVE-2025-51427 | HIGH | 7.3 | 0.5% | May 19, 2026 | An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t... |
| CVE-2025-40904 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an... |
| CVE-2025-40903 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid... |
| CVE-2025-40902 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p... |
| CVE-2025-40901 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation... |
| CVE-2025-40900 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-14575 | LOW | 1.8 | 0.1% | May 19, 2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (... |
| CVE-2025-15609 | HIGH | 7.5 | 0.4% | May 19, 2026 | The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now