2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25026 | MEDIUM | 4.3 | 0.2% | May 28, 2025 | IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authent... |
| CVE-2025-25025 | MEDIUM | 5.3 | 0.3% | May 28, 2025 | IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error... |
| CVE-2025-2796 | MEDIUM | 5.3 | 0.2% | May 27, 2025 | On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection confi... |
| CVE-2025-40911 | MEDIUM | 6.5 | 0.3% | May 27, 2025 | Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address s... |
| CVE-2025-5283 | MEDIUM | 5.4 | 0.5% | May 27, 2025 | Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-5281 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially... |
| CVE-2025-5278 | MEDIUM | 4.4 | 0.2% | May 27, 2025 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The... |
| CVE-2025-5198 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a s... |
| CVE-2025-5067 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform U... |
| CVE-2025-5066 | MEDIUM | 6.5 | 0.4% | May 27, 2025 | Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker wh... |
| CVE-2025-5065 | MEDIUM | 6.5 | 0.4% | May 27, 2025 | Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t... |
| CVE-2025-5064 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t... |
| CVE-2025-46173 | MEDIUM | 6.1 | 0.3% | May 27, 2025 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the fee... |
| CVE-2025-45475 | MEDIUM | 5.4 | 0.3% | May 27, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. |
| CVE-2025-22377 | MEDIUM | 6.5 | 0.3% | May 27, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-27701 | MEDIUM | 5.5 | 0.1% | May 27, 2025 | In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after ca... |
| CVE-2025-3704 | MEDIUM | 5.9 | 0.2% | May 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions V... |
| CVE-2025-5271 | MEDIUM | 6.5 | 0.2% | May 27, 2025 | Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab... |
| CVE-2025-5267 | MEDIUM | 5.4 | 0.2% | May 27, 2025 | A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious... |
| CVE-2025-5266 | MEDIUM | 4.3 | 0.3% | May 27, 2025 | Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak... |
| CVE-2025-5265 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in... |
| CVE-2025-5264 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into... |
| CVE-2025-5263 | MEDIUM | 4.3 | 0.2% | May 27, 2025 | Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea... |
| CVE-2025-4412 | MEDIUM | 4.8 | 0.1% | May 27, 2025 | On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it ... |
| CVE-2025-23393 | MEDIUM | 5.6 | 0.3% | May 27, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now