2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46822 | HIGH | 7.7 | 4.0% | May 21, 2025 | OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. P... |
| CVE-2025-5030 | HIGH | 8.1 | 2.6% | May 21, 2025 | A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affect... |
| CVE-2025-4416 | HIGH | 7.5 | 0.3% | May 21, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio... |
| CVE-2025-20256 | HIGH | 7.2 | 0.5% | May 21, 2025 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network... |
| CVE-2025-20152 | HIGH | 8.6 | 0.6% | May 21, 2025 | A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen... |
| CVE-2025-20113 | HIGH | 7.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges... |
| CVE-2025-4008 | HIGH | 8.8 | 93.9% | May 21, 2025 | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer ... |
| CVE-2025-48207 | HIGH | 8.6 | 0.3% | May 21, 2025 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48205 | HIGH | 8.6 | 0.3% | May 21, 2025 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48201 | HIGH | 8.6 | 0.3% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. |
| CVE-2025-27998 | HIGH | 8.4 | 0.2% | May 21, 2025 | An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe... |
| CVE-2025-27997 | HIGH | 8.4 | 0.2% | May 21, 2025 | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script... |
| CVE-2025-48416 | HIGH | 8.1 | 0.5% | May 21, 2025 | An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image fo... |
| CVE-2025-40775 | HIGH | 7.5 | 10.8% | May 21, 2025 | When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta... |
| CVE-2025-1416 | HIGH | 7 | 0.2% | May 21, 2025 | In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities res... |
| CVE-2025-4803 | HIGH | 7.2 | 0.6% | May 21, 2025 | The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection ... |
| CVE-2025-48413 | HIGH | 7.7 | 0.2% | May 21, 2025 | The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr... |
| CVE-2025-1712 | HIGH | 8.8 | 0.7% | May 21, 2025 | Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat... |
| CVE-2025-4998 | HIGH | 7.1 | 0.4% | May 20, 2025 | A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerab... |
| CVE-2025-4997 | HIGH | 7.1 | 0.4% | May 20, 2025 | A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function U... |
| CVE-2025-4364 | HIGH | 8.7 | 0.4% | May 20, 2025 | The affected products could allow an unauthenticated attacker to access system information that could enable further acc... |
| CVE-2025-48391 | HIGH | 7.5 | 0.3% | May 20, 2025 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API |
| CVE-2025-37991 | HIGH | 7.8 | 0.2% | May 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that ... |
| CVE-2025-22157 | HIGH | 8.8 | 0.4% | May 20, 2025 | This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and... |
| CVE-2025-37981 | HIGH | 7.8 | 0.2% | May 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now