2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24022 | HIGH | 8.5 | 0.5% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is po... |
| CVE-2025-3600 | HIGH | 7.5 | 19.1% | May 14, 2025 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may... |
| CVE-2025-3931 | HIGH | 7.8 | 0.2% | May 14, 2025 | A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's ... |
| CVE-2025-4430 | HIGH | 8.6 | 0.3% | May 14, 2025 | Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in ve... |
| CVE-2025-3834 | HIGH | 8.1 | 1.3% | May 14, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU Histo... |
| CVE-2025-3833 | HIGH | 8.1 | 27.8% | May 14, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MF... |
| CVE-2025-26864 | HIGH | 7.5 | 0.7% | May 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili... |
| CVE-2025-26795 | HIGH | 7.5 | 0.7% | May 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili... |
| CVE-2025-2875 | HIGH | 8.7 | 0.3% | May 14, 2025 | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of... |
| CVE-2025-26646 | HIGH | 8 | 1.1% | May 13, 2025 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized att... |
| CVE-2025-43572 | HIGH | 7.8 | 0.2% | May 13, 2025 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary... |
| CVE-2025-43571 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-43570 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-43569 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2025-43568 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-43565 | HIGH | 8.4 | 9.2% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c... |
| CVE-2025-43554 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2025-43553 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that... |
| CVE-2025-43549 | HIGH | 7.8 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-43548 | HIGH | 7.8 | 0.2% | May 13, 2025 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary... |
| CVE-2025-24308 | HIGH | 8.7 | 0.1% | May 13, 2025 | Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privi... |
| CVE-2025-22892 | HIGH | 7.1 | 0.2% | May 13, 2025 | Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 ... |
| CVE-2025-22843 | HIGH | 8.8 | 0.1% | May 13, 2025 | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow... |
| CVE-2025-21094 | HIGH | 8.7 | 0.1% | May 13, 2025 | Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a p... |
| CVE-2025-20618 | HIGH | 8.3 | 0.1% | May 13, 2025 | Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now