2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36579 | MEDIUM | 5.1 | 0.2% | Apr 16, 2026 | Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph... |
| CVE-2025-15621 | MEDIUM | 5.7 | 0.1% | Apr 16, 2026 | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re... |
| CVE-2025-12624 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail... |
| CVE-2025-6024 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script... |
| CVE-2025-13364 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2025-15636 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You... |
| CVE-2025-15635 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro... |
| CVE-2025-53444 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i... |
| CVE-2025-12141 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif... |
| CVE-2025-52641 | MEDIUM | 5.3 | 0.1% | Apr 15, 2026 | HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str... |
| CVE-2025-15470 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th... |
| CVE-2025-15565 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check... |
| CVE-2025-68649 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze... |
| CVE-2025-65136 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v... |
| CVE-2025-65134 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms... |
| CVE-2025-65132 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a... |
| CVE-2025-61886 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-61624 | MEDIUM | 6.5 | 0.5% | Apr 14, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For... |
| CVE-2025-59809 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P... |
| CVE-2025-69993 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This... |
| CVE-2025-69893 | MEDIUM | 4.6 | 0.2% | Apr 14, 2026 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13... |
| CVE-2025-13822 | MEDIUM | 5.3 | 0.4% | Apr 14, 2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati... |
| CVE-2025-40745 | MEDIUM | 6.3 | 0.1% | Apr 14, 2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V... |
| CVE-2025-70936 | MEDIUM | 5.4 | 0.1% | Apr 13, 2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl... |
| CVE-2025-63743 | MEDIUM | 5.4 | 0.3% | Apr 13, 2026 | Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now