2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30100 | HIGH | 7.8 | 0.1% | Apr 16, 2025 | Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low pr... |
| CVE-2025-32385 | MEDIUM | 6.5 | 0.2% | Apr 16, 2025 | EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to displ... |
| CVE-2025-30215 | CRITICAL | 9.6 | 0.5% | Apr 16, 2025 | NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f... |
| CVE-2025-32435 | LOW | 2.6 | 0.3% | Apr 15, 2025 | Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could poten... |
| CVE-2025-32388 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsa... |
| CVE-2025-25458 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2. |
| CVE-2025-25453 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2. |
| CVE-2025-22911 | MEDIUM | 5.6 | 0.3% | Apr 15, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function. |
| CVE-2025-32923 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmas... |
| CVE-2025-32784 | HIGH | 7.5 | 0.2% | Apr 15, 2025 | conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025... |
| CVE-2025-32782 | MEDIUM | 5.3 | 0.3% | Apr 15, 2025 | Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently u... |
| CVE-2025-31950 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger energy consumption information of other users. |
| CVE-2025-31945 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | An unauthenticated attacker can obtain other users' charger information. |
| CVE-2025-31654 | MEDIUM | 6.9 | 0.2% | Apr 15, 2025 | An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). |
| CVE-2025-31360 | HIGH | 7.5 | 0.4% | Apr 15, 2025 | Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. |
| CVE-2025-31147 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. |
| CVE-2025-30984 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools s... |
| CVE-2025-30982 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookPr... |
| CVE-2025-30970 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottwallick Easy ... |
| CVE-2025-30967 | CRITICAL | 9.6 | 0.2% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i... |
| CVE-2025-30966 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a throu... |
| CVE-2025-30512 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g.... |
| CVE-2025-30510 | CRITICAL | 9.8 | 0.2% | Apr 15, 2025 | An attacker can upload an arbitrary file instead of a plant image. |
| CVE-2025-30257 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. |
| CVE-2025-29471 | HIGH | 8.3 | 5.9% | Apr 15, 2025 | Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now