2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29955 | MEDIUM | 5.5 | 0.5% | May 13, 2025 | Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. |
| CVE-2025-29954 | MEDIUM | 5.9 | 1.1% | May 13, 2025 | Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke... |
| CVE-2025-29839 | MEDIUM | 4 | 0.4% | May 13, 2025 | Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. |
| CVE-2025-29837 | MEDIUM | 5.5 | 0.5% | May 13, 2025 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to dis... |
| CVE-2025-29836 | MEDIUM | 6.5 | 1.1% | May 13, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-29835 | MEDIUM | 6.5 | 1.0% | May 13, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-29832 | MEDIUM | 6.5 | 1.0% | May 13, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-29830 | MEDIUM | 6.5 | 1.0% | May 13, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis... |
| CVE-2025-29829 | MEDIUM | 5.5 | 0.4% | May 13, 2025 | Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info... |
| CVE-2025-27488 | MEDIUM | 6.7 | 0.4% | May 13, 2025 | Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. |
| CVE-2025-26685 | MEDIUM | 6.5 | 0.6% | May 13, 2025 | Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a... |
| CVE-2025-26684 | MEDIUM | 6.7 | 0.4% | May 13, 2025 | External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil... |
| CVE-2025-47204 | MEDIUM | 6.1 | 0.4% | May 13, 2025 | An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour... |
| CVE-2025-46721 | MEDIUM | 6.1 | 0.2% | May 13, 2025 | nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 all... |
| CVE-2025-45867 | MEDIUM | 5.4 | 3.4% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the f... |
| CVE-2025-45866 | MEDIUM | 5.4 | 0.3% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the f... |
| CVE-2025-45864 | MEDIUM | 5.4 | 3.4% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the... |
| CVE-2025-45859 | MEDIUM | 5.4 | 3.5% | May 13, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formM... |
| CVE-2025-44039 | MEDIUM | 5.1 | 0.2% | May 13, 2025 | CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. ... |
| CVE-2025-22859 | MEDIUM | 5.3 | 0.5% | May 13, 2025 | A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 th... |
| CVE-2025-4649 | MEDIUM | 4.9 | 0.3% | May 13, 2025 | Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not co... |
| CVE-2025-4648 | MEDIUM | 5.9 | 0.2% | May 13, 2025 | The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user w... |
| CVE-2025-4647 | MEDIUM | 4.8 | 0.2% | May 13, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon we... |
| CVE-2025-40583 | MEDIUM | 6.7 | 0.1% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed... |
| CVE-2025-40578 | MEDIUM | 5.3 | 0.2% | May 13, 2025 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not pro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now