2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4478 | MEDIUM | 6.5 | 0.4% | May 16, 2025 | A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a se... |
| CVE-2025-47794 | MEDIUM | 4.3 | 0.4% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Ne... |
| CVE-2025-47793 | MEDIUM | 6.5 | 0.7% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured fo... |
| CVE-2025-47792 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty app... |
| CVE-2025-47791 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and N... |
| CVE-2025-47790 | MEDIUM | 6.4 | 0.3% | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextc... |
| CVE-2025-32962 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for ... |
| CVE-2025-40907 | MEDIUM | 5.3 | 0.5% | May 16, 2025 | FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The in... |
| CVE-2025-2306 | MEDIUM | 5.9 | 0.4% | May 16, 2025 | An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows us... |
| CVE-2025-40632 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to mod... |
| CVE-2025-40631 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header a... |
| CVE-2025-40630 | MEDIUM | 6.1 | 0.4% | May 16, 2025 | Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to... |
| CVE-2025-4768 | MEDIUM | 6.3 | 0.3% | May 16, 2025 | A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects... |
| CVE-2025-4767 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is t... |
| CVE-2025-4679 | MEDIUM | 6.5 | 1.0% | May 16, 2025 | A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive in... |
| CVE-2025-4755 | MEDIUM | 5.3 | 5.0% | May 16, 2025 | A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the... |
| CVE-2025-4753 | MEDIUM | 6.9 | 0.9% | May 16, 2025 | A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue... |
| CVE-2025-3624 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).T... |
| CVE-2025-1531 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Op... |
| CVE-2025-4752 | MEDIUM | 6.9 | 0.9% | May 16, 2025 | A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this ... |
| CVE-2025-4750 | MEDIUM | 6.9 | 0.9% | May 16, 2025 | A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). This issu... |
| CVE-2025-3516 | MEDIUM | 5.9 | 0.3% | May 16, 2025 | The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting ... |
| CVE-2025-3201 | MEDIUM | 5.9 | 0.2% | May 16, 2025 | The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some... |
| CVE-2025-1245 | MEDIUM | 6.5 | 0.1% | May 16, 2025 | Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component... |
| CVE-2025-4759 | MEDIUM | 5.3 | 0.4% | May 16, 2025 | Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now