2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30665 | MEDIUM | 6.5 | 0.5% | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-47709 | MEDIUM | 6.5 | 0.2% | May 14, 2025 | Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affect... |
| CVE-2025-47706 | MEDIUM | 4.8 | 0.2% | May 14, 2025 | Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services w... |
| CVE-2025-47705 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remo... |
| CVE-2025-47704 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki... |
| CVE-2025-47703 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-47702 | MEDIUM | 6.1 | 0.2% | May 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Prov... |
| CVE-2025-44186 | MEDIUM | 5.4 | 0.1% | May 14, 2025 | SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operatio... |
| CVE-2025-44184 | MEDIUM | 4.8 | 0.2% | May 14, 2025 | SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi... |
| CVE-2025-3932 | MEDIUM | 6.5 | 0.3% | May 14, 2025 | It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach... |
| CVE-2025-26784 | MEDIUM | 6.5 | 0.2% | May 14, 2025 | An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-47778 | MEDIUM | 6.1 | 0.4% | May 14, 2025 | Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,... |
| CVE-2025-24969 | MEDIUM | 5 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts pictur... |
| CVE-2025-24785 | MEDIUM | 4.3 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a... |
| CVE-2025-24026 | MEDIUM | 5.3 | 0.3% | May 14, 2025 | iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of ... |
| CVE-2025-24021 | MEDIUM | 5 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi... |
| CVE-2025-3769 | MEDIUM | 5.3 | 0.3% | May 14, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc... |
| CVE-2025-4520 | MEDIUM | 4.3 | 0.3% | May 14, 2025 | The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2025-4574 | MEDIUM | 6.5 | 0.4% | May 13, 2025 | In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some c... |
| CVE-2025-47905 | MEDIUM | 5.4 | 0.3% | May 13, 2025 | Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via H... |
| CVE-2025-43566 | MEDIUM | 6.8 | 37.7% | May 13, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restr... |
| CVE-2025-43551 | MEDIUM | 5.5 | 0.2% | May 13, 2025 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-30316 | MEDIUM | 5.4 | 0.2% | May 13, 2025 | Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ... |
| CVE-2025-30315 | MEDIUM | 6.1 | 0.2% | May 13, 2025 | Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ... |
| CVE-2025-30314 | MEDIUM | 6.1 | 0.3% | May 13, 2025 | Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now