2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34491 | HIGH | 8.8 | 0.7% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attac... |
| CVE-2025-31651 | CRITICAL | 9.8 | 4.2% | Apr 28, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely r... |
| CVE-2025-31650 | HIGH | 7.5 | 66.9% | Apr 28, 2025 | Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority header... |
| CVE-2025-4033 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected ... |
| CVE-2025-4032 | HIGH | 8.1 | 3.2% | Apr 28, 2025 | A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as cri... |
| CVE-2025-34490 | MEDIUM | 6.5 | 0.6% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot... |
| CVE-2025-34489 | HIGH | 7.8 | 0.3% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escal... |
| CVE-2025-4031 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnera... |
| CVE-2025-4030 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This ... |
| CVE-2025-4029 | HIGH | 7.8 | 0.3% | Apr 28, 2025 | A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-4028 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected ... |
| CVE-2025-4027 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected ... |
| CVE-2025-4026 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.... |
| CVE-2025-46614 | LOW | 3.3 | 0.1% | Apr 28, 2025 | In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a... |
| CVE-2025-43857 | MEDIUM | 6.5 | 0.4% | Apr 28, 2025 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.... |
| CVE-2025-43854 | MEDIUM | 6.1 | 0.2% | Apr 28, 2025 | DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in t... |
| CVE-2025-4025 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne... |
| CVE-2025-4024 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un... |
| CVE-2025-25776 | MEDIUM | 5 | 0.2% | Apr 28, 2025 | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Tick... |
| CVE-2025-23377 | LOW | 3.4 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output ... |
| CVE-2025-23376 | MEDIUM | 4.4 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Speci... |
| CVE-2025-23375 | HIGH | 7.8 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability... |
| CVE-2025-4023 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff... |
| CVE-2025-4022 | HIGH | 8.8 | 0.4% | Apr 28, 2025 | A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affe... |
| CVE-2025-4021 | HIGH | 7.5 | 0.3% | Apr 28, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now