2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1732 | MEDIUM | 6.7 | 0.2% | Apr 22, 2025 | An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware vers... |
| CVE-2025-1731 | HIGH | 7.8 | 0.9% | Apr 22, 2025 | An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware ... |
| CVE-2025-3856 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea... |
| CVE-2025-3855 | MEDIUM | 5.3 | 0.4% | Apr 22, 2025 | A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by t... |
| CVE-2025-3854 | HIGH | 8.6 | 0.5% | Apr 22, 2025 | A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E... |
| CVE-2025-3850 | LOW | 2.7 | 0.5% | Apr 22, 2025 | A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu... |
| CVE-2025-3849 | MEDIUM | 6.5 | 0.3% | Apr 22, 2025 | A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects... |
| CVE-2025-2987 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated... |
| CVE-2025-3847 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part ... |
| CVE-2025-3846 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is ... |
| CVE-2025-3845 | CRITICAL | 9.8 | 0.6% | Apr 21, 2025 | A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner... |
| CVE-2025-3843 | MEDIUM | 6.5 | 0.3% | Apr 21, 2025 | A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown functi... |
| CVE-2025-3842 | CRITICAL | 9.8 | 0.5% | Apr 21, 2025 | A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse... |
| CVE-2025-32958 | CRITICAL | 9.8 | 0.5% | Apr 21, 2025 | Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses act... |
| CVE-2025-32956 | HIGH | 8 | 0.5% | Apr 21, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ... |
| CVE-2025-32955 | MEDIUM | 6 | 0.2% | Apr 21, 2025 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to befor... |
| CVE-2025-3841 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9... |
| CVE-2025-28104 | CRITICAL | 9.1 | 0.3% | Apr 21, 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. |
| CVE-2025-28103 | MEDIUM | 6.4 | 0.2% | Apr 21, 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. |
| CVE-2025-27086 | HIGH | 8.1 | 0.3% | Apr 21, 2025 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. |
| CVE-2025-29446 | — | — | 0.2% | Apr 21, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-28102 | MEDIUM | 6.1 | 0.2% | Apr 21, 2025 | A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2025-28099 | MEDIUM | 4.3 | 0.3% | Apr 21, 2025 | opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp, |
| CVE-2025-23174 | HIGH | 7.5 | 0.3% | Apr 21, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-43922 | HIGH | 8.1 | 0.1% | Apr 21, 2025 | The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now