2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48473 | MEDIUM | 4.3 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation fro... |
| CVE-2025-4081 | MEDIUM | 4.8 | 0.1% | May 29, 2025 | Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints al... |
| CVE-2025-5320 | MEDIUM | 6.3 | 0.2% | May 29, 2025 | A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is... |
| CVE-2025-46080 | MEDIUM | 5.3 | 0.4% | May 29, 2025 | HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr... |
| CVE-2025-46078 | MEDIUM | 5.3 | 0.3% | May 29, 2025 | HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server |
| CVE-2025-37999 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() aft... |
| CVE-2025-37998 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output... |
| CVE-2025-37997 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types ... |
| CVE-2025-37996 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u... |
| CVE-2025-37995 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for modul... |
| CVE-2025-37994 | MEDIUM | 5.5 | 0.2% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer acc... |
| CVE-2025-37993 | MEDIUM | 5.5 | 0.1% | May 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize ... |
| CVE-2025-33043 | MEDIUM | 6.1 | 0.2% | May 29, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp... |
| CVE-2025-48046 | MEDIUM | 5.3 | 0.5% | May 29, 2025 | An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /co... |
| CVE-2025-48388 | MEDIUM | 6.5 | 0.3% | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi... |
| CVE-2025-5286 | MEDIUM | 6.4 | 0.3% | May 29, 2025 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ pa... |
| CVE-2025-5122 | MEDIUM | 6.4 | 0.3% | May 29, 2025 | The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all v... |
| CVE-2025-4670 | MEDIUM | 5.4 | 0.3% | May 29, 2025 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored... |
| CVE-2025-5273 | MEDIUM | 6.9 | 0.3% | May 29, 2025 | Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa... |
| CVE-2025-4583 | MEDIUM | 5.4 | 0.2% | May 29, 2025 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-27703 | MEDIUM | 6 | 0.3% | May 28, 2025 | CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to ver... |
| CVE-2025-27702 | MEDIUM | 4.9 | 0.3% | May 28, 2025 | CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers... |
| CVE-2025-5256 | MEDIUM | 5.4 | 0.2% | May 28, 2025 | SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability... |
| CVE-2025-48747 | MEDIUM | 5 | 0.2% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor... |
| CVE-2025-47748 | MEDIUM | 5.3 | 0.3% | May 28, 2025 | Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now