2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26268 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted... |
| CVE-2025-25455 | HIGH | 7.5 | 0.5% | Apr 17, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2. |
| CVE-2025-25454 | HIGH | 7.5 | 0.5% | Apr 17, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2. |
| CVE-2025-32415 | HIGH | 7.5 | 0.5% | Apr 17, 2025 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer un... |
| CVE-2025-2947 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicio... |
| CVE-2025-29662 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system ... |
| CVE-2025-29661 | HIGH | 7.2 | 0.4% | Apr 17, 2025 | Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run. |
| CVE-2025-29181 | HIGH | 7.2 | 0.3% | Apr 17, 2025 | FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php. |
| CVE-2025-29180 | HIGH | 7.2 | 0.3% | Apr 17, 2025 | In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, a... |
| CVE-2025-29039 | HIGH | 7.2 | 1.0% | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8 |
| CVE-2025-43015 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces |
| CVE-2025-43014 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation |
| CVE-2025-43013 | HIGH | 7.5 | 0.1% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible |
| CVE-2025-43012 | CRITICAL | 9.8 | 0.7% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible |
| CVE-2025-42921 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin |
| CVE-2025-39596 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects ... |
| CVE-2025-39595 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Qu... |
| CVE-2025-39594 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autore... |
| CVE-2025-39588 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allow... |
| CVE-2025-39587 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calc... |
| CVE-2025-39586 | HIGH | 8.5 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileG... |
| CVE-2025-39583 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ... |
| CVE-2025-39580 | MEDIUM | 5.8 | 0.2% | Apr 17, 2025 | Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ... |
| CVE-2025-39569 | HIGH | 8.5 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbu... |
| CVE-2025-39568 | HIGH | 7.5 | 0.4% | Apr 17, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arture B.V. StoreContrl ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now