2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37841 | MEDIUM | 5.5 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: pm: cpupower: bench: Prevent NULL dereference on ma... |
| CVE-2025-37837 | MEDIUM | 5.5 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix warnings due to dmam_free... |
| CVE-2025-37836 | MEDIUM | 5.5 | 0.2% | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge... |
| CVE-2025-4376 | MEDIUM | 5.3 | 0.6% | May 9, 2025 | Improper Input Validation vulnerability in Sparx Systems Pro Cloud Server's WebEA model search field allows Cross-Site S... |
| CVE-2025-4375 | MEDIUM | 6.9 | 0.3% | May 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to p... |
| CVE-2025-4461 | MEDIUM | 5.4 | 0.5% | May 9, 2025 | A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unkno... |
| CVE-2025-4460 | MEDIUM | 4.8 | 0.5% | May 9, 2025 | A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown par... |
| CVE-2025-31946 | MEDIUM | 6.9 | 0.2% | May 8, 2025 | Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a cr... |
| CVE-2025-28074 | MEDIUM | 6.1 | 0.5% | May 8, 2025 | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vuln... |
| CVE-2025-46833 | MEDIUM | 4.6 | 0.2% | May 8, 2025 | Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versio... |
| CVE-2025-46336 | MEDIUM | 4.2 | 0.3% | May 8, 2025 | Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when usi... |
| CVE-2025-44023 | MEDIUM | 6.5 | 0.4% | May 8, 2025 | An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account... |
| CVE-2025-28073 | MEDIUM | 6.1 | 0.5% | May 8, 2025 | phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker ... |
| CVE-2025-27695 | MEDIUM | 4.9 | 0.6% | May 8, 2025 | Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high... |
| CVE-2025-30102 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low pri... |
| CVE-2025-30101 | MEDIUM | 6.3 | 0.1% | May 8, 2025 | Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vu... |
| CVE-2025-45847 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the ... |
| CVE-2025-43926 | MEDIUM | 6.1 | 0.2% | May 8, 2025 | An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateA... |
| CVE-2025-4207 | MEDIUM | 5.9 | 0.6% | May 8, 2025 | Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial ... |
| CVE-2025-45820 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/p... |
| CVE-2025-45819 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/au... |
| CVE-2025-45818 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/it... |
| CVE-2025-47729 | MEDIUM | 4.9 | 0.4% | May 8, 2025 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal... |
| CVE-2025-4208 | MEDIUM | 6.3 | 0.3% | May 8, 2025 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code E... |
| CVE-2025-3862 | MEDIUM | 5.4 | 0.2% | May 8, 2025 | Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now