2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26677 | HIGH | 7.5 | 1.4% | May 13, 2025 | Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over... |
| CVE-2025-24063 | HIGH | 7.8 | 0.6% | May 13, 2025 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-21264 | HIGH | 7.1 | 0.6% | May 13, 2025 | Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se... |
| CVE-2025-0035 | HIGH | 7.3 | 0.2% | May 13, 2025 | Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential... |
| CVE-2025-4428 | HIGH | 8.8 | 87.5% | May 13, 2025 | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms all... |
| CVE-2025-4427 | HIGH | 7.5 | 99.6% | May 13, 2025 | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a... |
| CVE-2025-47276 | HIGH | 7.5 | 0.2% | May 13, 2025 | Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating syste... |
| CVE-2025-30207 | HIGH | 7.5 | 0.5% | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff... |
| CVE-2025-28055 | HIGH | 7.5 | 0.5% | May 13, 2025 | upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit |
| CVE-2025-28057 | HIGH | 7.2 | 0.4% | May 13, 2025 | owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order. |
| CVE-2025-22460 | HIGH | 7.8 | 0.3% | May 13, 2025 | Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to e... |
| CVE-2025-32917 | HIGH | 8.8 | 0.3% | May 13, 2025 | Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p... |
| CVE-2025-4646 | HIGH | 7.2 | 0.4% | May 13, 2025 | Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This... |
| CVE-2025-40582 | HIGH | 8.5 | 0.2% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed... |
| CVE-2025-40581 | HIGH | 8.4 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed... |
| CVE-2025-40580 | HIGH | 7.8 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40579 | HIGH | 7.8 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40574 | HIGH | 8.5 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices... |
| CVE-2025-40556 | HIGH | 7.1 | 0.2% | May 13, 2025 | A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet AT... |
| CVE-2025-32454 | HIGH | 7.8 | 0.2% | May 13, 2025 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualizat... |
| CVE-2025-31930 | HIGH | 8.8 | 0.2% | May 13, 2025 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph ... |
| CVE-2025-30176 | HIGH | 8.7 | 0.5% | May 13, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N... |
| CVE-2025-30175 | HIGH | 8.7 | 0.5% | May 13, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N... |
| CVE-2025-30174 | HIGH | 8.7 | 0.5% | May 13, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N... |
| CVE-2025-24510 | HIGH | 7.1 | 0.2% | May 13, 2025 | A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle spec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now