2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36220 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to... |
| CVE-2025-71211 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-71210 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-31973 | CRITICAL | 9.8 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd... |
| CVE-2025-33255 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial... |
| CVE-2025-11024 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So... |
| CVE-2025-27851 | CRITICAL | 9.3 | 0.1% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac... |
| CVE-2025-65719 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user... |
| CVE-2025-6577 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So... |
| CVE-2025-40949 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ... |
| CVE-2025-69691 | CRITICAL | 9.9 | 0.5% | May 8, 2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ... |
| CVE-2025-69690 | CRITICAL | 9.1 | 0.6% | May 8, 2026 | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob... |
| CVE-2025-69599 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e... |
| CVE-2025-67887 | CRITICAL | 9.8 | 1.5% | May 8, 2026 | 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla... |
| CVE-2025-63704 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ... |
| CVE-2025-63703 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). |
| CVE-2025-63706 | CRITICAL | 9.8 | 1.5% | May 7, 2026 | NPM package next-npm-version1.0.1 is vulnerable to Command injection. |
| CVE-2025-1978 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage ... |
| CVE-2025-9661 | CRITICAL | 9.8 | 0.9% | May 7, 2026 | OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B... |
| CVE-2025-59852 | CRITICAL | 9.1 | 0.1% | May 6, 2026 | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted ove... |
| CVE-2025-59851 | CRITICAL | 9.8 | 0.2% | May 6, 2026 | HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatc... |
| CVE-2025-13618 | CRITICAL | 9.8 | 0.3% | May 5, 2026 | The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th... |
| CVE-2025-13605 | CRITICAL | 9.3 | 0.2% | May 4, 2026 | 3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to exec... |
| CVE-2025-70067 | CRITICAL | 9.8 | 0.4% | May 4, 2026 | Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiM... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now