2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41225 | HIGH | 8.8 | 0.2% | May 20, 2025 | The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to creat... |
| CVE-2025-26086 | HIGH | 7.5 | 11.3% | May 20, 2025 | An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parame... |
| CVE-2025-47941 | HIGH | 7.2 | 0.4% | May 20, 2025 | TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS an... |
| CVE-2025-47940 | HIGH | 7.2 | 0.4% | May 20, 2025 | TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.... |
| CVE-2025-41231 | HIGH | 7.3 | 0.2% | May 20, 2025 | VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Fo... |
| CVE-2025-41230 | HIGH | 7.5 | 0.4% | May 20, 2025 | VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port ... |
| CVE-2025-41229 | HIGH | 8.2 | 0.6% | May 20, 2025 | VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 ... |
| CVE-2025-30193 | HIGH | 7.5 | 0.6% | May 20, 2025 | In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP conn... |
| CVE-2025-37892 | HIGH | 7.8 | 0.2% | May 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob(... |
| CVE-2025-2929 | HIGH | 7.1 | 0.2% | May 20, 2025 | The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2025-4971 | HIGH | 8.5 | 0.5% | May 20, 2025 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execu... |
| CVE-2025-3079 | HIGH | 8.7 | 0.6% | May 20, 2025 | A passback vulnerability which relates to office/small office multifunction printers and laser printers. |
| CVE-2025-3078 | HIGH | 8.7 | 0.6% | May 20, 2025 | A passback vulnerability which relates to production printers and office multifunction printers. |
| CVE-2025-1308 | HIGH | 8.4 | 0.1% | May 19, 2025 | A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions. |
| CVE-2025-47949 | HIGH | 7.5 | 0.5% | May 19, 2025 | samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to ver... |
| CVE-2025-47944 | HIGH | 7.5 | 0.7% | May 19, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1... |
| CVE-2025-47935 | HIGH | 7.5 | 0.7% | May 19, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource ... |
| CVE-2025-39393 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital ... |
| CVE-2025-39392 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apa... |
| CVE-2025-39372 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPres... |
| CVE-2025-39366 | HIGH | 8.8 | 0.3% | May 19, 2025 | Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-39365 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProje... |
| CVE-2025-39357 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ... |
| CVE-2025-39355 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Servic... |
| CVE-2025-39352 | HIGH | 8.2 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now