2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4062HIGH7.8A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by ...
CVE-2025-3301LOW1DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on al...
CVE-2025-2817HIGH8.8Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man...
CVE-2025-4061HIGH7.8A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0...
CVE-2025-4060CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affe...
CVE-2025-4035MEDIUM4.3A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix...
CVE-2025-4059HIGH7.8A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affec...
CVE-2025-4058CRITICAL9.8A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an un...
CVE-2025-3929MEDIUM6.1An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted H...
CVE-2025-3891HIGH7.5A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to...
CVE-2025-30194HIGH7.5When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by craftin...
CVE-2025-1194MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe...
CVE-2025-3452MEDIUM4.3The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-2893MEDIUM5.4The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-46343MEDIUM5.4n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t...
CVE-2025-46338MEDIUM6.1Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulner...
CVE-2025-46330LOW3.3libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat...
CVE-2025-46329LOW3.3libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to...
CVE-2025-46761Rejected reason: Not used
CVE-2025-46760Rejected reason: Not used
CVE-2025-46759Rejected reason: Not used
CVE-2025-46758Rejected reason: Not used
CVE-2025-46757Rejected reason: Not used
CVE-2025-46756Rejected reason: Not used
CVE-2025-46755Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now