2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3509 | HIGH | 7.2 | 1.2% | Apr 17, 2025 | A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute... |
| CVE-2025-3246 | HIGH | 7.6 | 0.3% | Apr 17, 2025 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scr... |
| CVE-2025-3124 | MEDIUM | 4.3 | 0.4% | Apr 17, 2025 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of... |
| CVE-2025-29461 | HIGH | 7.6 | 0.3% | Apr 17, 2025 | An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ p... |
| CVE-2025-29460 | HIGH | 7.6 | 0.3% | Apr 17, 2025 | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the ... |
| CVE-2025-29459 | HIGH | 7.6 | 0.4% | Apr 17, 2025 | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Suppli... |
| CVE-2025-29458 | HIGH | 7.6 | 0.4% | Apr 17, 2025 | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: t... |
| CVE-2025-29457 | HIGH | 7.6 | 0.4% | Apr 17, 2025 | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: ... |
| CVE-2025-29456 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29453 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29455 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29454 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29452 | HIGH | 7.6 | 0.3% | Apr 17, 2025 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component. |
| CVE-2025-29451 | HIGH | 7.6 | 0.3% | Apr 17, 2025 | An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component. |
| CVE-2025-29450 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp... |
| CVE-2025-29449 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio... |
| CVE-2025-3765 | HIGH | 8.8 | 0.4% | Apr 17, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen... |
| CVE-2025-3764 | HIGH | 8.8 | 0.4% | Apr 17, 2025 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi... |
| CVE-2025-3763 | HIGH | 7.8 | 0.3% | Apr 17, 2025 | A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu... |
| CVE-2025-3762 | CRITICAL | 9.8 | 0.6% | Apr 17, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-29316 | MEDIUM | 6.2 | 0.2% | Apr 17, 2025 | An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t... |
| CVE-2025-29722 | MEDIUM | 6.3 | 0.2% | Apr 17, 2025 | A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat... |
| CVE-2025-28101 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele... |
| CVE-2025-28009 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2... |
| CVE-2025-26269 | MEDIUM | 5.5 | 0.2% | Apr 17, 2025 | DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now