2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0126 | HIGH | 8.3 | 0.3% | Apr 11, 2025 | When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to imperson... |
| CVE-2025-0125 | MEDIUM | 6.9 | 0.3% | Apr 11, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
| CVE-2025-0124 | LOW | 3.8 | 0.3% | Apr 11, 2025 | An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacke... |
| CVE-2025-0122 | MEDIUM | 5.1 | 0.2% | Apr 11, 2025 | A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated atta... |
| CVE-2025-0121 | MEDIUM | 6.8 | 0.1% | Apr 11, 2025 | A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-pri... |
| CVE-2025-0120 | HIGH | 7 | 0.1% | Apr 11, 2025 | A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices al... |
| CVE-2025-32809 | MEDIUM | 5.4 | 0.2% | Apr 11, 2025 | W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus ... |
| CVE-2025-32808 | HIGH | 7.7 | 0.3% | Apr 11, 2025 | W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into t... |
| CVE-2025-32807 | MEDIUM | 5.3 | 0.5% | Apr 11, 2025 | A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host... |
| CVE-2025-29918 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ... |
| CVE-2025-29917 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th... |
| CVE-2025-29916 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Da... |
| CVE-2025-29915 | HIGH | 7.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th... |
| CVE-2025-3469 | NONE | 0 | 0.3% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-32700 | LOW | 2.3 | 0.3% | Apr 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulne... |
| CVE-2025-32699 | LOW | 2.1 | 0.3% | Apr 10, 2025 | Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.... |
| CVE-2025-32698 | LOW | 2.1 | 0.3% | Apr 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera... |
| CVE-2025-32697 | NONE | 0 | 0.3% | Apr 10, 2025 | Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated w... |
| CVE-2025-32696 | NONE | 0 | 0.3% | Apr 10, 2025 | Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated w... |
| CVE-2025-23010 | HIGH | 7.2 | 0.4% | Apr 10, 2025 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and... |
| CVE-2025-23009 | HIGH | 7.2 | 0.3% | Apr 10, 2025 | A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attac... |
| CVE-2025-23008 | HIGH | 7.2 | 0.3% | Apr 10, 2025 | An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low ... |
| CVE-2025-22232 | MEDIUM | 5.3 | 0.3% | Apr 10, 2025 | Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to... |
| CVE-2025-24866 | LOW | 2.7 | 0.2% | Apr 10, 2025 | Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing us... |
| CVE-2025-32382 | LOW | 1.8 | 0.3% | Apr 10, 2025 | Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection de... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now