2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5105 | HIGH | 7.3 | 0.4% | May 23, 2025 | A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknow... |
| CVE-2025-41407 | HIGH | 8.3 | 1.2% | May 23, 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. |
| CVE-2025-3893 | HIGH | 8.6 | 0.3% | May 23, 2025 | While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this a... |
| CVE-2025-36527 | HIGH | 8.3 | 20.2% | May 23, 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
| CVE-2025-5100 | HIGH | 8 | 0.2% | May 23, 2025 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory cor... |
| CVE-2025-48371 | HIGH | 8.8 | 0.4% | May 22, 2025 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg... |
| CVE-2025-47181 | HIGH | 8.8 | 0.5% | May 22, 2025 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a... |
| CVE-2025-48372 | HIGH | 7.3 | 0.2% | May 22, 2025 | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time... |
| CVE-2025-48075 | HIGH | 7.5 | 0.4% | May 22, 2025 | Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber... |
| CVE-2025-30172 | HIGH | 8.9 | 0.5% | May 22, 2025 | Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This... |
| CVE-2025-47780 | HIGH | 7.8 | 0.2% | May 22, 2025 | Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste... |
| CVE-2025-46715 | HIGH | 7.8 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-45472 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou... |
| CVE-2025-33137 | HIGH | 8.8 | 0.3% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau... |
| CVE-2025-33136 | HIGH | 8.8 | 0.3% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau... |
| CVE-2025-45468 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust... |
| CVE-2025-5080 | HIGH | 8.8 | 0.8% | May 22, 2025 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFil... |
| CVE-2025-5024 | HIGH | 7.4 | 0.8% | May 22, 2025 | A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated atta... |
| CVE-2025-45471 | HIGH | 8.8 | 0.3% | May 22, 2025 | Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl... |
| CVE-2025-32813 | HIGH | 7.2 | 42.3% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur. |
| CVE-2025-4979 | HIGH | 7.5 | 0.4% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor... |
| CVE-2025-46714 | HIGH | 7.8 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-46713 | HIGH | 7.8 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-3943 | HIGH | 7.5 | 7.1% | May 22, 2025 | Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX... |
| CVE-2025-3942 | HIGH | 7.5 | 0.2% | May 22, 2025 | Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niaga... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now