2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59853 | MEDIUM | 5.3 | 0.2% | May 6, 2026 | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack tr... |
| CVE-2025-31970 | MEDIUM | 6.1 | 0.1% | May 6, 2026 | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic... |
| CVE-2025-61669 | MEDIUM | 6.1 | 0.3% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query pa... |
| CVE-2025-52206 | MEDIUM | 4.7 | 0.2% | May 5, 2026 | ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage. |
| CVE-2025-42611 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | RouterOS provides various services that rely on correct verification of client and server certificates to secure confide... |
| CVE-2025-47406 | MEDIUM | 5.5 | 0.1% | May 4, 2026 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. |
| CVE-2025-70071 | MEDIUM | 5.9 | 0.5% | May 4, 2026 | An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA... |
| CVE-2025-70072 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:... |
| CVE-2025-70070 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet... |
| CVE-2025-14726 | MEDIUM | 6.5 | 0.8% | May 2, 2026 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ... |
| CVE-2025-69606 | MEDIUM | 6.1 | 0.4% | May 1, 2026 | Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t... |
| CVE-2025-36335 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo... |
| CVE-2025-36122 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could... |
| CVE-2025-14688 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-56537 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute... |
| CVE-2025-56536 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri... |
| CVE-2025-56535 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2025-56534 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t... |
| CVE-2025-10503 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ... |
| CVE-2025-60887 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m... |
| CVE-2025-10539 | MEDIUM | 4.8 | 0.2% | Apr 28, 2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p... |
| CVE-2025-15626 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application |
| CVE-2025-67259 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user... |
| CVE-2025-59308 | MEDIUM | 4.7 | 0.2% | Apr 24, 2026 | In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ... |
| CVE-2025-61872 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now