2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2272 | HIGH | 7.3 | 0.1% | May 22, 2025 | Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, H... |
| CVE-2025-41403 | HIGH | 8.3 | 1.4% | May 22, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching ... |
| CVE-2025-3836 | HIGH | 8.3 | 4.6% | May 22, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev... |
| CVE-2025-3887 | HIGH | 8.8 | 0.7% | May 22, 2025 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-3884 | HIGH | 7.5 | 1.6% | May 22, 2025 | Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-3883 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw... |
| CVE-2025-3882 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-3881 | HIGH | 8.8 | 0.8% | May 22, 2025 | eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2025-3486 | HIGH | 8.8 | 1.6% | May 22, 2025 | Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-3483 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3482 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-3481 | HIGH | 7.8 | 0.5% | May 22, 2025 | MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-2759 | HIGH | 7.8 | 0.1% | May 22, 2025 | GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta... |
| CVE-2025-5059 | HIGH | 7.2 | 0.4% | May 21, 2025 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown p... |
| CVE-2025-34025 | HIGH | 8.6 | 0.4% | May 21, 2025 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab... |
| CVE-2025-47947 | HIGH | 7.5 | 0.6% | May 21, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions ... |
| CVE-2025-34026 | HIGH | 7.5 | 83.4% | May 21, 2025 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy ... |
| CVE-2025-45753 | HIGH | 7.2 | 0.4% | May 21, 2025 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P... |
| CVE-2025-44040 | HIGH | 7.2 | 0.4% | May 21, 2025 | An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi... |
| CVE-2025-45752 | HIGH | 7.2 | 0.5% | May 21, 2025 | A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t... |
| CVE-2025-3751 | HIGH | 7 | 0.3% | May 21, 2025 | The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection atta... |
| CVE-2025-2261 | HIGH | 7 | 0.3% | May 21, 2025 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within ... |
| CVE-2025-48063 | HIGH | 8.8 | 0.8% | May 21, 2025 | XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc... |
| CVE-2025-48060 | HIGH | 7.5 | 0.4% | May 21, 2025 | jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio... |
| CVE-2025-47291 | HIGH | 7.5 | 0.2% | May 21, 2025 | containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now