2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27523 | HIGH | 8.7 | 0.3% | May 15, 2025 | XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Des... |
| CVE-2025-3053 | HIGH | 8.8 | 0.9% | May 15, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod... |
| CVE-2025-4579 | HIGH | 7.2 | 0.3% | May 15, 2025 | The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and... |
| CVE-2025-47885 | HIGH | 8.8 | 0.5% | May 14, 2025 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Hea... |
| CVE-2025-44879 | HIGH | 7.5 | 0.4% | May 14, 2025 | WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerabi... |
| CVE-2025-26783 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330,... |
| CVE-2025-4640 | HIGH | 8.3 | 0.3% | May 14, 2025 | Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default... |
| CVE-2025-33104 | HIGH | 7.6 | 0.2% | May 14, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2025-2900 | HIGH | 7.5 | 0.2% | May 14, 2025 | IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 th... |
| CVE-2025-0131 | HIGH | 7.1 | 0.1% | May 14, 2025 | An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto N... |
| CVE-2025-4639 | HIGH | 8.8 | 0.4% | May 14, 2025 | CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe... |
| CVE-2025-4637 | HIGH | 8.7 | 0.4% | May 14, 2025 | Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file... |
| CVE-2025-30664 | HIGH | 8.2 | 0.2% | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege v... |
| CVE-2025-30663 | HIGH | 7 | 0.1% | May 14, 2025 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escal... |
| CVE-2025-0130 | HIGH | 7.5 | 0.4% | May 14, 2025 | A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenti... |
| CVE-2025-47710 | HIGH | 7.4 | 0.3% | May 14, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
| CVE-2025-47708 | HIGH | 8.8 | 0.2% | May 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forg... |
| CVE-2025-47707 | HIGH | 7.5 | 0.4% | May 14, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ... |
| CVE-2025-47701 | HIGH | 8.8 | 0.2% | May 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This is... |
| CVE-2025-40595 | HIGH | 7.2 | 0.3% | May 14, 2025 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By... |
| CVE-2025-3909 | HIGH | 8.1 | 0.4% | May 14, 2025 | Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the fil... |
| CVE-2025-3875 | HIGH | 7.5 | 0.3% | May 14, 2025 | Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t... |
| CVE-2025-26785 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-47782 | HIGH | 8.9 | 0.4% | May 14, 2025 | motionEye is an online interface for the software motion, a video surveillance program with motion detection. In version... |
| CVE-2025-47775 | HIGH | 8.6 | 0.4% | May 14, 2025 | Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now