2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32803 | MEDIUM | 4 | 0.2% | May 28, 2025 | In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, ... |
| CVE-2025-31501 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. |
| CVE-2025-31500 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. |
| CVE-2025-30087 | MEDIUM | 6.1 | 0.3% | May 28, 2025 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete... |
| CVE-2025-1461 | MEDIUM | 5.6 | 0.3% | May 28, 2025 | Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsa... |
| CVE-2025-5257 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u... |
| CVE-2025-48931 | MEDIUM | 5.5 | 0.1% | May 28, 2025 | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibiliti... |
| CVE-2025-48930 | MEDIUM | 5.3 | 0.1% | May 28, 2025 | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content ma... |
| CVE-2025-48928 | MEDIUM | 4 | 0.4% | May 28, 2025 | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent... |
| CVE-2025-48927 | MEDIUM | 5.3 | 7.9% | May 28, 2025 | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap... |
| CVE-2025-48746 | MEDIUM | 6.5 | 0.2% | May 28, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe... |
| CVE-2025-36572 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image f... |
| CVE-2025-32802 | MEDIUM | 6.1 | 0.2% | May 28, 2025 | Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M... |
| CVE-2025-40651 | MEDIUM | 5.1 | 0.4% | May 28, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute ... |
| CVE-2025-4493 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT req... |
| CVE-2025-5297 | MEDIUM | 6.6 | 0.2% | May 28, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issu... |
| CVE-2025-40673 | MEDIUM | 5.3 | 0.3% | May 28, 2025 | A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoi... |
| CVE-2025-4963 | MEDIUM | 6.4 | 0.2% | May 28, 2025 | The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u... |
| CVE-2025-5082 | MEDIUM | 6.1 | 0.3% | May 28, 2025 | The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ paramete... |
| CVE-2025-47294 | MEDIUM | 5.3 | 0.7% | May 28, 2025 | A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may all... |
| CVE-2025-27526 | MEDIUM | 6.5 | 0.7% | May 28, 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through... |
| CVE-2025-27522 | MEDIUM | 6.5 | 0.7% | May 28, 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through... |
| CVE-2025-5025 | MEDIUM | 4.8 | 0.2% | May 28, 2025 | libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is n... |
| CVE-2025-4947 | MEDIUM | 6.5 | 0.2% | May 28, 2025 | libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I... |
| CVE-2025-25029 | MEDIUM | 6.5 | 0.3% | May 28, 2025 | IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now