2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27580 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de... |
| CVE-2025-25046 | LOW | 3.7 | 0.1% | Apr 23, 2025 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parame... |
| CVE-2025-25045 | MEDIUM | 4.3 | 0.2% | Apr 23, 2025 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro... |
| CVE-2025-46400 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input ... |
| CVE-2025-46399 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu... |
| CVE-2025-46398 | MEDIUM | 5.5 | 0.2% | Apr 23, 2025 | In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v... |
| CVE-2025-46397 | HIGH | 7.8 | 0.3% | Apr 23, 2025 | A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spli... |
| CVE-2025-32818 | HIGH | 7.5 | 0.8% | Apr 23, 2025 | A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated... |
| CVE-2025-28169 | HIGH | 8.1 | 0.3% | Apr 23, 2025 | BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the ma... |
| CVE-2025-3673 | — | — | — | Apr 23, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3092.. Reason: This candidate is a... |
| CVE-2025-3907 | MEDIUM | 4.3 | 0.1% | Apr 23, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a... |
| CVE-2025-3904 | HIGH | 7.3 | 0.2% | Apr 23, 2025 | Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*. |
| CVE-2025-3903 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. |
| CVE-2025-3902 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class... |
| CVE-2025-3901 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S... |
| CVE-2025-3900 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al... |
| CVE-2025-2773 | HIGH | 7.2 | 1.8% | Apr 23, 2025 | BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2025-2772 | MEDIUM | 6.5 | 0.4% | Apr 23, 2025 | BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner... |
| CVE-2025-2771 | MEDIUM | 5.3 | 0.7% | Apr 23, 2025 | BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp... |
| CVE-2025-2770 | MEDIUM | 6.5 | 0.4% | Apr 23, 2025 | BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al... |
| CVE-2025-2769 | HIGH | 7.8 | 0.2% | Apr 23, 2025 | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc... |
| CVE-2025-2768 | HIGH | 7.8 | 0.2% | Apr 23, 2025 | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc... |
| CVE-2025-2767 | CRITICAL | 9.6 | 0.5% | Apr 23, 2025 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-2765 | HIGH | 8.8 | 0.3% | Apr 23, 2025 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability al... |
| CVE-2025-2764 | HIGH | 8 | 0.2% | Apr 23, 2025 | CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now