2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45614 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information... |
| CVE-2025-45613 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati... |
| CVE-2025-45610 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen... |
| CVE-2025-45609 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf... |
| CVE-2025-45608 | HIGH | 7.5 | 0.3% | May 5, 2025 | Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens... |
| CVE-2025-4279 | HIGH | 8.8 | 0.6% | May 5, 2025 | The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-46559 | HIGH | 7.5 | 0.4% | May 5, 2025 | Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m... |
| CVE-2025-4282 | HIGH | 8.8 | 0.3% | May 5, 2025 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th... |
| CVE-2025-4096 | HIGH | 8.8 | 0.5% | May 5, 2025 | Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit he... |
| CVE-2025-4050 | HIGH | 8.8 | 0.5% | May 5, 2025 | Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced ... |
| CVE-2025-45237 | HIGH | 7.5 | 0.4% | May 5, 2025 | Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c... |
| CVE-2025-45242 | HIGH | 7.7 | 0.4% | May 5, 2025 | Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method ... |
| CVE-2025-0217 | HIGH | 7.8 | 0.2% | May 5, 2025 | BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A loc... |
| CVE-2025-45322 | HIGH | 8.8 | 0.4% | May 5, 2025 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the... |
| CVE-2025-45321 | HIGH | 8.8 | 0.4% | May 5, 2025 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph... |
| CVE-2025-28062 | HIGH | 8.1 | 0.8% | May 5, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allow... |
| CVE-2025-27920 | HIGH | 8.8 | 1.8% | May 5, 2025 | Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us... |
| CVE-2025-4272 | HIGH | 7.3 | 0.2% | May 5, 2025 | A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is... |
| CVE-2025-4270 | HIGH | 7.5 | 9.7% | May 5, 2025 | A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f... |
| CVE-2025-4267 | HIGH | 7.2 | 0.4% | May 5, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. Th... |
| CVE-2025-4260 | HIGH | 8.3 | 0.5% | May 5, 2025 | A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is... |
| CVE-2025-20671 | HIGH | 7 | 0.1% | May 5, 2025 | In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv... |
| CVE-2025-20668 | HIGH | 7.8 | 0.1% | May 5, 2025 | In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2025-20667 | HIGH | 7.5 | 0.4% | May 5, 2025 | In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote informat... |
| CVE-2025-20666 | HIGH | 7.5 | 0.7% | May 5, 2025 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now