2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48695 | MEDIUM | 6.4 | 0.2% | May 23, 2025 | An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to... |
| CVE-2025-4594 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat... |
| CVE-2025-48701 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used. |
| CVE-2025-2394 | MEDIUM | 4.7 | 0.2% | May 23, 2025 | Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alib... |
| CVE-2025-4692 | MEDIUM | 6.8 | 0.3% | May 23, 2025 | Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation b... |
| CVE-2025-4338 | MEDIUM | 6.9 | 0.2% | May 22, 2025 | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the netwo... |
| CVE-2025-4975 | MEDIUM | 4.8 | 0.1% | May 22, 2025 | When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notific... |
| CVE-2025-48374 | MEDIUM | 5.5 | 0.2% | May 22, 2025 | zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to v... |
| CVE-2025-48369 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48368 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48366 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20... |
| CVE-2025-48066 | MEDIUM | 5.5 | 0.1% | May 22, 2025 | wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an ... |
| CVE-2025-30173 | MEDIUM | 6.7 | 0.3% | May 22, 2025 | File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff... |
| CVE-2025-30170 | MEDIUM | 5.9 | 0.3% | May 22, 2025 | Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf... |
| CVE-2025-30169 | MEDIUM | 6.7 | 0.3% | May 22, 2025 | File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become... |
| CVE-2025-48061 | MEDIUM | 5.6 | 0.1% | May 22, 2025 | wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in... |
| CVE-2025-47779 | MEDIUM | 6.5 | 0.4% | May 22, 2025 | Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste... |
| CVE-2025-46716 | MEDIUM | 5.5 | 0.2% | May 22, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve... |
| CVE-2025-33138 | MEDIUM | 6.1 | 0.2% | May 22, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-4366 | MEDIUM | 6.1 | 0.4% | May 22, 2025 | A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP r... |
| CVE-2025-2506 | MEDIUM | 5.3 | 0.3% | May 22, 2025 | When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user w... |
| CVE-2025-23183 | MEDIUM | 6.1 | 0.2% | May 22, 2025 | CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2025-23182 | MEDIUM | 4.3 | 0.2% | May 22, 2025 | CWE-203: Observable Discrepancy |
| CVE-2025-32915 | MEDIUM | 5.5 | 0.1% | May 22, 2025 | Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.... |
| CVE-2025-32815 | MEDIUM | 6.5 | 32.8% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now