2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32027 | MEDIUM | 6.1 | 0.2% | Apr 10, 2025 | Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenari... |
| CVE-2025-29150 | MEDIUM | 4.3 | 0.3% | Apr 10, 2025 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. |
| CVE-2025-0362 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.1... |
| CVE-2025-32743 | CRITICAL | 9 | 0.4% | Apr 10, 2025 | In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca... |
| CVE-2025-32395 | MEDIUM | 6 | 1.7% | Apr 10, 2025 | Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of ... |
| CVE-2025-32391 | MEDIUM | 4.6 | 0.3% | Apr 10, 2025 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file ... |
| CVE-2025-32383 | HIGH | 7.2 | 0.2% | Apr 10, 2025 | MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model an... |
| CVE-2025-2469 | MEDIUM | 5.3 | 0.3% | Apr 10, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. T... |
| CVE-2025-29088 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial ... |
| CVE-2025-29017 | HIGH | 8.8 | 0.7% | Apr 10, 2025 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file uplo... |
| CVE-2025-30148 | MEDIUM | 5.4 | 0.2% | Apr 10, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to e... |
| CVE-2025-2408 | MEDIUM | 5.3 | 0.3% | Apr 10, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17... |
| CVE-2025-27813 | HIGH | 8.1 | 0.1% | Apr 10, 2025 | MSI Center before 2.0.52.0 has Missing PE Signature Validation. |
| CVE-2025-27812 | HIGH | 8.1 | 0.1% | Apr 10, 2025 | MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation. |
| CVE-2025-25197 | MEDIUM | 5.4 | 0.3% | Apr 10, 2025 | Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page ... |
| CVE-2025-1677 | HIGH | 7.5 | 0.3% | Apr 10, 2025 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and... |
| CVE-2025-32755 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De... |
| CVE-2025-32754 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on... |
| CVE-2025-1073 | HIGH | 7.5 | 0.2% | Apr 10, 2025 | Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unaut... |
| CVE-2025-31411 | MEDIUM | 5.9 | 0.3% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aribhour Linet ERP-Wooco... |
| CVE-2025-27350 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice V... |
| CVE-2025-22375 | CRITICAL | 9.3 | 0.4% | Apr 10, 2025 | An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an... |
| CVE-2025-22374 | MEDIUM | 6 | 0.3% | Apr 10, 2025 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAu... |
| CVE-2025-23386 | HIGH | 7.8 | 0.1% | Apr 10, 2025 | A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera... |
| CVE-2025-27081 | MEDIUM | 6.8 | 0.2% | Apr 10, 2025 | A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now