2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37840 | HIGH | 7.8 | 0.3% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixe... |
| CVE-2025-37839 | HIGH | 7.8 | 0.3% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal em... |
| CVE-2025-4377 | HIGH | 8.3 | 0.6% | May 9, 2025 | Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnera... |
| CVE-2025-3462 | HIGH | 8.4 | 0.5% | May 9, 2025 | "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici... |
| CVE-2025-4462 | HIGH | 8.8 | 1.5% | May 9, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. This issue affects... |
| CVE-2025-4459 | HIGH | 8.8 | 0.7% | May 9, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected... |
| CVE-2025-4458 | HIGH | 8.8 | 0.7% | May 9, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affec... |
| CVE-2025-3713 | HIGH | 8.7 | 1.0% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.21... |
| CVE-2025-3712 | HIGH | 8.7 | 1.0% | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.21... |
| CVE-2025-4455 | HIGH | 7.3 | 0.2% | May 9, 2025 | A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects s... |
| CVE-2025-4446 | HIGH | 8.6 | 0.5% | May 9, 2025 | A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the... |
| CVE-2025-4440 | HIGH | 8.6 | 0.5% | May 8, 2025 | A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the funct... |
| CVE-2025-47733 | HIGH | 7.5 | 1.5% | May 8, 2025 | Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over ... |
| CVE-2025-33072 | HIGH | 7.5 | 1.4% | May 8, 2025 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-29827 | HIGH | 8.8 | 1.2% | May 8, 2025 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-27578 | HIGH | 8.7 | 0.8% | May 8, 2025 | Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM fil... |
| CVE-2025-1331 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t... |
| CVE-2025-1330 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on ... |
| CVE-2025-1329 | HIGH | 7.8 | 0.2% | May 8, 2025 | IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on t... |
| CVE-2025-4098 | HIGH | 8.4 | 0.2% | May 8, 2025 | Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could a... |
| CVE-2025-1948 | HIGH | 7.5 | 0.6% | May 8, 2025 | In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 set... |
| CVE-2025-26847 | HIGH | 7.5 | 0.3% | May 8, 2025 | An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked. |
| CVE-2025-45846 | HIGH | 8.8 | 0.5% | May 8, 2025 | ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in th... |
| CVE-2025-45845 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet... |
| CVE-2025-45844 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now