2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45843 | HIGH | 8.8 | 0.6% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter... |
| CVE-2025-45842 | HIGH | 8.8 | 0.8% | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g paramet... |
| CVE-2025-26842 | HIGH | 7.5 | 0.3% | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-ma... |
| CVE-2025-47730 | HIGH | 7.5 | 0.3% | May 8, 2025 | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM ... |
| CVE-2025-41450 | HIGH | 8.2 | 0.3% | May 8, 2025 | Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to v... |
| CVE-2025-3759 | HIGH | 8.7 | 0.2% | May 8, 2025 | Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authenticati... |
| CVE-2025-3758 | HIGH | 8.7 | 0.2% | May 8, 2025 | WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Ret... |
| CVE-2025-40846 | HIGH | 7.1 | 0.3% | May 8, 2025 | Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing ... |
| CVE-2025-1254 | HIGH | 7.4 | 0.2% | May 8, 2025 | Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Bu... |
| CVE-2025-1253 | HIGH | 7.8 | 0.1% | May 8, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI... |
| CVE-2025-1252 | HIGH | 7.1 | 0.1% | May 8, 2025 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags... |
| CVE-2025-37825 | HIGH | 7.1 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix out-of-bounds access in nvmet_enable_por... |
| CVE-2025-37823 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeu... |
| CVE-2025-37822 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building ... |
| CVE-2025-37819 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_g... |
| CVE-2025-37817 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: mcb: fix a double free bug in chameleon_parse_gdd()... |
| CVE-2025-37810 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not ... |
| CVE-2025-37803 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmab... |
| CVE-2025-3419 | HIGH | 7.5 | 0.6% | May 8, 2025 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary fil... |
| CVE-2025-46727 | HIGH | 7.5 | 0.9% | May 7, 2025 | Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses qu... |
| CVE-2025-46265 | HIGH | 8.8 | 0.3% | May 7, 2025 | On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may b... |
| CVE-2025-43878 | HIGH | 8.3 | 0.1% | May 7, 2025 | When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may ... |
| CVE-2025-41433 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is conf... |
| CVE-2025-41431 | HIGH | 8.7 | 0.4% | May 7, 2025 | When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Micro... |
| CVE-2025-41414 | HIGH | 8.7 | 0.4% | May 7, 2025 | When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now