2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4186 | MEDIUM | 6.3 | 0.4% | May 2, 2025 | A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown funct... |
| CVE-2025-4185 | MEDIUM | 6.3 | 7.0% | May 2, 2025 | A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some... |
| CVE-2025-4178 | MEDIUM | 5.4 | 0.5% | May 1, 2025 | A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and class... |
| CVE-2025-27365 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-1333 | MEDIUM | 6.5 | 0.2% | May 1, 2025 | IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through... |
| CVE-2025-4175 | MEDIUM | 6.3 | 0.4% | May 1, 2025 | A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. T... |
| CVE-2025-46632 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to ... |
| CVE-2025-46631 | MEDIUM | 6.5 | 4.9% | May 1, 2025 | Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ... |
| CVE-2025-46630 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote ... |
| CVE-2025-46629 | MEDIUM | 6.5 | 1.0% | May 1, 2025 | Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote... |
| CVE-2025-3517 | MEDIUM | 6.3 | 0.3% | May 1, 2025 | Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM us... |
| CVE-2025-36558 | MEDIUM | 6.1 | 13.3% | May 1, 2025 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for aut... |
| CVE-2025-46565 | MEDIUM | 5.3 | 1.1% | May 1, 2025 | Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the cont... |
| CVE-2025-46345 | MEDIUM | 6.9 | 0.3% | May 1, 2025 | Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify t... |
| CVE-2025-44867 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via th... |
| CVE-2025-44866 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the lev... |
| CVE-2025-44865 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the ena... |
| CVE-2025-44864 | MEDIUM | 6.3 | 1.1% | May 1, 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the mod... |
| CVE-2025-44863 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio... |
| CVE-2025-44862 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw fu... |
| CVE-2025-44861 | MEDIUM | 6.3 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVer... |
| CVE-2025-44860 | MEDIUM | 6.5 | 0.9% | May 1, 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process functio... |
| CVE-2025-32890 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of e... |
| CVE-2025-32887 | MEDIUM | 6.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next ho... |
| CVE-2025-32886 | MEDIUM | 5.5 | 0.1% | May 1, 2025 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now