2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51846 | HIGH | 8.7 | 0.6% | Apr 30, 2026 | CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o... |
| CVE-2025-14576 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio... |
| CVE-2025-50328 | HIGH | 7.3 | 0.3% | Apr 29, 2026 | A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th... |
| CVE-2025-67223 | HIGH | 7.5 | 0.6% | Apr 28, 2026 | The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w... |
| CVE-2025-48431 | HIGH | 7.5 | 1.1% | Apr 28, 2026 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach... |
| CVE-2025-69428 | HIGH | 7.5 | 0.3% | Apr 27, 2026 | An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi... |
| CVE-2025-69689 | HIGH | 8.8 | 0.1% | Apr 27, 2026 | The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial... |
| CVE-2025-70994 | HIGH | 7.3 | 0.3% | Apr 23, 2026 | Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent... |
| CVE-2025-36074 | HIGH | 7.2 | 0.3% | Apr 23, 2026 | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m... |
| CVE-2025-31958 | HIGH | 8.2 | 0.2% | Apr 21, 2026 | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh... |
| CVE-2025-14362 | HIGH | 7.3 | 0.2% | Apr 21, 2026 | The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin... |
| CVE-2025-13826 | HIGH | 8.2 | 0.3% | Apr 21, 2026 | Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu... |
| CVE-2025-65104 | HIGH | 7.5 | 0.2% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect... |
| CVE-2025-46607 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46606 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46605 | HIGH | 7.2 | 0.3% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-36568 | HIGH | 7.8 | 0.1% | Apr 17, 2026 | Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio... |
| CVE-2025-15624 | HIGH | 7.5 | 0.4% | Apr 17, 2026 | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID... |
| CVE-2025-15623 | HIGH | 7.5 | 0.3% | Apr 17, 2026 | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau... |
| CVE-2025-54502 | HIGH | 7.5 | 0.1% | Apr 16, 2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker... |
| CVE-2025-14868 | HIGH | 8.8 | 0.4% | Apr 16, 2026 | The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr... |
| CVE-2025-63029 | HIGH | 7.6 | 0.3% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar... |
| CVE-2025-67841 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue. |
| CVE-2025-40899 | HIGH | 8.9 | 0.3% | Apr 15, 2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat... |
| CVE-2025-40897 | HIGH | 8.1 | 0.3% | Apr 15, 2026 | An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now