2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32968 | HIGH | 8.8 | 0.4% | Apr 23, 2025 | XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it ... |
| CVE-2025-32966 | CRITICAL | 9.8 | 3.9% | Apr 23, 2025 | DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE... |
| CVE-2025-21605 | HIGH | 7.5 | 0.8% | Apr 23, 2025 | Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An un... |
| CVE-2025-46393 | MEDIUM | 5.3 | 0.3% | Apr 23, 2025 | In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the renderi... |
| CVE-2025-45428 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ... |
| CVE-2025-45427 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ... |
| CVE-2025-43965 | HIGH | 7.5 | 0.5% | Apr 23, 2025 | In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. |
| CVE-2025-43716 | MEDIUM | 5.8 | 1.2% | Apr 23, 2025 | A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to... |
| CVE-2025-2703 | MEDIUM | 6.8 | 10.6% | Apr 23, 2025 | The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif... |
| CVE-2025-42605 | CRITICAL | 9.3 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ... |
| CVE-2025-42604 | MEDIUM | 6.9 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker... |
| CVE-2025-42603 | HIGH | 8.7 | 0.3% | Apr 23, 2025 | This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the respo... |
| CVE-2025-42602 | HIGH | 8.2 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API end... |
| CVE-2025-42601 | HIGH | 8.2 | 0.3% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API... |
| CVE-2025-42600 | HIGH | 8.2 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password... |
| CVE-2025-1054 | MEDIUM | 6.4 | 0.2% | Apr 23, 2025 | The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2025-3530 | HIGH | 7.5 | 0.4% | Apr 23, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t... |
| CVE-2025-3529 | HIGH | 8.2 | 0.3% | Apr 23, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-2595 | MEDIUM | 5.3 | 0.4% | Apr 23, 2025 | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa... |
| CVE-2025-0618 | MEDIUM | 6.5 | 0.6% | Apr 23, 2025 | A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec... |
| CVE-2025-1056 | MEDIUM | 6.5 | 0.2% | Apr 23, 2025 | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the ... |
| CVE-2025-0926 | HIGH | 7.3 | 0.2% | Apr 23, 2025 | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to ... |
| CVE-2025-46224 | — | — | — | Apr 23, 2025 | Rejected reason: Not used |
| CVE-2025-46223 | — | — | — | Apr 23, 2025 | Rejected reason: Not used |
| CVE-2025-46222 | — | — | — | Apr 23, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now