2025 CVE Vulnerabilities
45,294 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43851 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43850 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43849 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-29573 | MEDIUM | 6.1 | 0.2% | May 5, 2025 | Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms mo... |
| CVE-2025-4282 | HIGH | 8.8 | 0.3% | May 5, 2025 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th... |
| CVE-2025-4096 | HIGH | 8.8 | 0.5% | May 5, 2025 | Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit he... |
| CVE-2025-4052 | CRITICAL | 9.8 | 0.6% | May 5, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced... |
| CVE-2025-4051 | MEDIUM | 6.3 | 0.3% | May 5, 2025 | Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced... |
| CVE-2025-4050 | HIGH | 8.8 | 0.5% | May 5, 2025 | Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced ... |
| CVE-2025-45239 | MEDIUM | 5.3 | 0.7% | May 5, 2025 | An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal. |
| CVE-2025-45238 | CRITICAL | 9.1 | 0.6% | May 5, 2025 | foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method. |
| CVE-2025-45237 | HIGH | 7.5 | 0.4% | May 5, 2025 | Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c... |
| CVE-2025-45236 | MEDIUM | 5.4 | 0.3% | May 5, 2025 | A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to exe... |
| CVE-2025-43848 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43847 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43846 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43845 | CRITICAL | 9.8 | 0.8% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43844 | CRITICAL | 9.8 | 2.1% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-45242 | HIGH | 7.7 | 0.4% | May 5, 2025 | Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method ... |
| CVE-2025-45240 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php. |
| CVE-2025-43915 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, ... |
| CVE-2025-43843 | CRITICAL | 9.8 | 2.3% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-43842 | CRITICAL | 9.8 | 2.1% | May 5, 2025 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu... |
| CVE-2025-24977 | CRITICAL | 9.1 | 0.8% | May 5, 2025 | OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manag... |
| CVE-2025-1992 | MEDIUM | 6.5 | 0.3% | May 5, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now