2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43962 | CRITICAL | 9.1 | 0.4% | Apr 21, 2025 | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing... |
| CVE-2025-43961 | CRITICAL | 9.1 | 0.4% | Apr 21, 2025 | In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser. |
| CVE-2025-43955 | MEDIUM | 6.8 | 0.3% | Apr 20, 2025 | TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr... |
| CVE-2025-43954 | MEDIUM | 6.1 | 0.2% | Apr 20, 2025 | QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set. |
| CVE-2025-3830 | CRITICAL | 9.8 | 0.4% | Apr 20, 2025 | A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerabi... |
| CVE-2025-3829 | CRITICAL | 9.8 | 0.5% | Apr 20, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is... |
| CVE-2025-3828 | CRITICAL | 9.8 | 0.5% | Apr 20, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s... |
| CVE-2025-3827 | CRITICAL | 9.8 | 0.5% | Apr 20, 2025 | A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil... |
| CVE-2025-3826 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management ... |
| CVE-2025-3825 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Manage... |
| CVE-2025-3824 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. ... |
| CVE-2025-3823 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System ... |
| CVE-2025-3822 | MEDIUM | 5.4 | 0.4% | Apr 20, 2025 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl... |
| CVE-2025-3821 | MEDIUM | 5.4 | 0.3% | Apr 20, 2025 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as pr... |
| CVE-2025-43929 | HIGH | 7.8 | 0.2% | Apr 20, 2025 | open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that ma... |
| CVE-2025-43928 | CRITICAL | 9.8 | 0.8% | Apr 20, 2025 | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../... |
| CVE-2025-43921 | MEDIUM | 5.3 | 0.4% | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/cr... |
| CVE-2025-43920 | HIGH | 8.1 | 0.5% | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated ... |
| CVE-2025-43919 | HIGH | 7.5 | 1.4% | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ dir... |
| CVE-2025-43918 | MEDIUM | 6.4 | 0.1% | Apr 19, 2025 | SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a ... |
| CVE-2025-3820 | HIGH | 8.8 | 8.1% | Apr 19, 2025 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this ... |
| CVE-2025-3819 | CRITICAL | 9.8 | 0.4% | Apr 19, 2025 | A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi... |
| CVE-2025-3818 | MEDIUM | 6.3 | 0.3% | Apr 19, 2025 | A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._... |
| CVE-2025-43917 | HIGH | 8.2 | 0.1% | Apr 19, 2025 | In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst... |
| CVE-2025-3817 | HIGH | 8.8 | 0.4% | Apr 19, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now