2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3928 | HIGH | 8.8 | 1.9% | Apr 25, 2025 | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. Accordi... |
| CVE-2025-2070 | MEDIUM | 5.1 | 0.1% | Apr 25, 2025 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the syst... |
| CVE-2025-2069 | MEDIUM | 5.1 | 0.2% | Apr 25, 2025 | A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted ur... |
| CVE-2025-2068 | MEDIUM | 5.1 | 0.1% | Apr 25, 2025 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url... |
| CVE-2025-46618 | MEDIUM | 6.1 | 22.0% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab |
| CVE-2025-46433 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible |
| CVE-2025-46432 | MEDIUM | 6.5 | 0.8% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs |
| CVE-2025-43862 | HIGH | 7.6 | 0.3% | Apr 25, 2025 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify... |
| CVE-2025-43016 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
| CVE-2025-3647 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they a... |
| CVE-2025-3645 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users'... |
| CVE-2025-3644 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not ... |
| CVE-2025-3643 | MEDIUM | 5.4 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cros... |
| CVE-2025-3642 | HIGH | 8.8 | 0.8% | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default... |
| CVE-2025-3641 | HIGH | 8.8 | 0.8% | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default... |
| CVE-2025-3640 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access so... |
| CVE-2025-3638 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to pr... |
| CVE-2025-3637 | LOW | 3.1 | 0.3% | Apr 25, 2025 | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CS... |
| CVE-2025-3636 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficien... |
| CVE-2025-3635 | LOW | 3.5 | 0.2% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log ... |
| CVE-2025-3628 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student... |
| CVE-2025-3627 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other stu... |
| CVE-2025-3625 | HIGH | 7.1 | 0.4% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about s... |
| CVE-2025-32432 | CRITICAL | 10 | 99.8% | Apr 25, 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from vers... |
| CVE-2025-32045 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now