2025 CVE Vulnerabilities
45,180 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41235 | HIGH | 8.6 | 0.3% | May 30, 2025 | Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies. |
| CVE-2025-48477 | HIGH | 8.1 | 0.4% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires... |
| CVE-2025-48476 | HIGH | 8.8 | 0.4% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user rec... |
| CVE-2025-44906 | HIGH | 7.8 | 0.2% | May 30, 2025 | jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c. |
| CVE-2025-44905 | HIGH | 8.8 | 0.4% | May 30, 2025 | hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function. |
| CVE-2025-44904 | HIGH | 8.8 | 0.4% | May 30, 2025 | hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. |
| CVE-2025-44614 | HIGH | 7.5 | 0.2% | May 30, 2025 | Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile ... |
| CVE-2025-5307 | HIGH | 7.8 | 0.2% | May 29, 2025 | Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue t... |
| CVE-2025-31189 | HIGH | 8.2 | 0.2% | May 29, 2025 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1... |
| CVE-2025-5328 | HIGH | 8.8 | 1.0% | May 29, 2025 | A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the functio... |
| CVE-2025-5327 | HIGH | 8.8 | 0.4% | May 29, 2025 | A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of t... |
| CVE-2025-5326 | HIGH | 8.8 | 0.4% | May 29, 2025 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as cr... |
| CVE-2025-2518 | HIGH | 7.5 | 0.3% | May 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is v... |
| CVE-2025-46701 | HIGH | 7.3 | 2.6% | May 29, 2025 | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of ... |
| CVE-2025-46823 | HIGH | 8 | 0.3% | May 29, 2025 | openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In ver... |
| CVE-2025-48475 | HIGH | 8.1 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch... |
| CVE-2025-46722 | HIGH | 7.3 | 0.3% | May 29, 2025 | vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.... |
| CVE-2025-48474 | HIGH | 8.1 | 0.4% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec... |
| CVE-2025-48472 | HIGH | 8.1 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that... |
| CVE-2025-48390 | HIGH | 7.2 | 0.8% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code ... |
| CVE-2025-48389 | HIGH | 7.2 | 0.8% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser... |
| CVE-2025-45474 | HIGH | 7.3 | 0.3% | May 29, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. |
| CVE-2025-5334 | HIGH | 7.5 | 0.5% | May 29, 2025 | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des... |
| CVE-2025-48045 | HIGH | 8.7 | 0.6% | May 29, 2025 | An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials... |
| CVE-2025-4687 | HIGH | 7.2 | 0.4% | May 29, 2025 | In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now