2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4062 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by ... |
| CVE-2025-3301 | LOW | 1 | 0.2% | Apr 29, 2025 | DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on al... |
| CVE-2025-2817 | HIGH | 8.8 | 0.5% | Apr 29, 2025 | Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man... |
| CVE-2025-4061 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0... |
| CVE-2025-4060 | CRITICAL | 9.8 | 0.4% | Apr 29, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affe... |
| CVE-2025-4035 | MEDIUM | 4.3 | 0.3% | Apr 29, 2025 | A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix... |
| CVE-2025-4059 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affec... |
| CVE-2025-4058 | CRITICAL | 9.8 | 0.4% | Apr 29, 2025 | A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an un... |
| CVE-2025-3929 | MEDIUM | 6.1 | 0.5% | Apr 29, 2025 | An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted H... |
| CVE-2025-3891 | HIGH | 7.5 | 1.2% | Apr 29, 2025 | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to... |
| CVE-2025-30194 | HIGH | 7.5 | 2.0% | Apr 29, 2025 | When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by craftin... |
| CVE-2025-1194 | MEDIUM | 6.5 | 0.4% | Apr 29, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe... |
| CVE-2025-3452 | MEDIUM | 4.3 | 0.2% | Apr 29, 2025 | The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-2893 | MEDIUM | 5.4 | 0.2% | Apr 29, 2025 | The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-46343 | MEDIUM | 5.4 | 0.2% | Apr 29, 2025 | n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t... |
| CVE-2025-46338 | MEDIUM | 6.1 | 0.3% | Apr 29, 2025 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulner... |
| CVE-2025-46330 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat... |
| CVE-2025-46329 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to... |
| CVE-2025-46761 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46760 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46759 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46758 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46757 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46756 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
| CVE-2025-46755 | — | — | — | Apr 29, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now