2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46814 | HIGH | 7.5 | 0.3% | May 6, 2025 | FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr... |
| CVE-2025-2898 | HIGH | 8.8 | 0.3% | May 6, 2025 | IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a ... |
| CVE-2025-0984 | HIGH | 8.2 | 0.3% | May 6, 2025 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cr... |
| CVE-2025-46762 | HIGH | 8.1 | 1.4% | May 6, 2025 | Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar... |
| CVE-2025-2011 | HIGH | 7.5 | 46.7% | May 6, 2025 | The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter... |
| CVE-2025-27132 | HIGH | 7.8 | 0.1% | May 6, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-21475 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing escape code, when DisplayId is passed with large unsigned value. |
| CVE-2025-21470 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. |
| CVE-2025-21469 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. |
| CVE-2025-21468 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to w... |
| CVE-2025-21467 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. |
| CVE-2025-21462 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit. |
| CVE-2025-21460 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed cont... |
| CVE-2025-21459 | HIGH | 7.5 | 0.3% | May 6, 2025 | Transient DOS while parsing per STA profile in ML IE. |
| CVE-2025-21453 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential f... |
| CVE-2025-46589 | HIGH | 7.1 | 0.1% | May 6, 2025 | Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a... |
| CVE-2025-46588 | HIGH | 7.7 | 0.1% | May 6, 2025 | Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a... |
| CVE-2025-46585 | HIGH | 7 | 0.1% | May 6, 2025 | Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-2802 | HIGH | 7.3 | 0.4% | May 6, 2025 | The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,... |
| CVE-2025-3610 | HIGH | 8.8 | 0.5% | May 6, 2025 | The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to... |
| CVE-2025-46728 | HIGH | 7.5 | 0.6% | May 6, 2025 | cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enf... |
| CVE-2025-2509 | HIGH | 7.8 | 0.1% | May 6, 2025 | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address acc... |
| CVE-2025-46813 | HIGH | 7.5 | 0.3% | May 5, 2025 | Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd... |
| CVE-2025-46731 | HIGH | 7.2 | 1.2% | May 5, 2025 | Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch pri... |
| CVE-2025-45617 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now