2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48012 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Cre... |
| CVE-2025-48011 | MEDIUM | 4.8 | 0.3% | May 21, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ... |
| CVE-2025-48010 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ... |
| CVE-2025-45754 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inj... |
| CVE-2025-25539 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via... |
| CVE-2025-20267 | MEDIUM | 4.8 | 0.2% | May 21, 2025 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2025-20258 | MEDIUM | 5.4 | 0.2% | May 21, 2025 | A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitr... |
| CVE-2025-20257 | MEDIUM | 6.5 | 0.3% | May 21, 2025 | A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual... |
| CVE-2025-20255 | MEDIUM | 4.3 | 0.2% | May 21, 2025 | A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip... |
| CVE-2025-20250 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
| CVE-2025-20247 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
| CVE-2025-20246 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a... |
| CVE-2025-20114 | MEDIUM | 4.3 | 0.3% | May 21, 2025 | A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform... |
| CVE-2025-20112 | MEDIUM | 5.1 | 0.1% | May 21, 2025 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authentica... |
| CVE-2025-0372 | MEDIUM | 5.9 | 0.1% | May 21, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwo... |
| CVE-2025-48206 | MEDIUM | 6.1 | 0.2% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 allows XSS. |
| CVE-2025-48204 | MEDIUM | 6.8 | 1.5% | May 21, 2025 | The ns_backup extension through 13.0.0 for TYPO3 allows command injection. |
| CVE-2025-48203 | MEDIUM | 6.4 | 0.2% | May 21, 2025 | The cs_seo extension through 9.2.0 for TYPO3 allows XSS. |
| CVE-2025-48202 | MEDIUM | 5.3 | 0.2% | May 21, 2025 | The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-5029 | MEDIUM | 5.4 | 0.4% | May 21, 2025 | A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classifie... |
| CVE-2025-44895 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4B... |
| CVE-2025-44892 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_p... |
| CVE-2025-48417 | MEDIUM | 6.5 | 0.2% | May 21, 2025 | The certificate and private key used for providing transport layer security for connections to the web interface (TCP po... |
| CVE-2025-48415 | MEDIUM | 6.2 | 0.2% | May 21, 2025 | A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The ... |
| CVE-2025-1418 | MEDIUM | 5.1 | 0.2% | May 21, 2025 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which cont... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now