2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20963 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to w... |
| CVE-2025-20957 | HIGH | 7.8 | 0.1% | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary act... |
| CVE-2025-0669 | HIGH | 8.8 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOI... |
| CVE-2025-32405 | HIGH | 7.5 | 0.5% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that... |
| CVE-2025-32402 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that... |
| CVE-2025-32400 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-32399 | HIGH | 7.5 | 0.5% | May 7, 2025 | An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t... |
| CVE-2025-32398 | HIGH | 7.5 | 0.3% | May 7, 2025 | A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices ... |
| CVE-2025-32397 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-32396 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devic... |
| CVE-2025-4335 | HIGH | 8.8 | 0.3% | May 7, 2025 | The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and... |
| CVE-2025-3921 | HIGH | 8.2 | 0.4% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-3852 | HIGH | 8.8 | 0.4% | May 7, 2025 | The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.... |
| CVE-2025-0856 | HIGH | 7.3 | 0.2% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ... |
| CVE-2025-4372 | HIGH | 8.8 | 0.5% | May 6, 2025 | Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap... |
| CVE-2025-47420 | HIGH | 8.7 | 0.3% | May 6, 2025 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.2153... |
| CVE-2025-0853 | HIGH | 7.5 | 0.3% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' ... |
| CVE-2025-46573 | HIGH | 8.6 | 0.3% | May 6, 2025 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ... |
| CVE-2025-0649 | HIGH | 7.5 | 0.2% | May 6, 2025 | Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbound... |
| CVE-2025-46820 | HIGH | 7.1 | 0.2% | May 6, 2025 | phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom wo... |
| CVE-2025-46815 | HIGH | 8 | 0.4% | May 6, 2025 | The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API... |
| CVE-2025-30165 | HIGH | 8 | 0.5% | May 6, 2025 | vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, ... |
| CVE-2025-22476 | HIGH | 8 | 0.6% | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Element... |
| CVE-2025-22478 | HIGH | 8.1 | 0.2% | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit... |
| CVE-2025-22477 | HIGH | 8.8 | 0.3% | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now