2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65116 | MEDIUM | 5.5 | 0.1% | Apr 7, 2026 | Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati... |
| CVE-2025-13044 | MEDIUM | 6.2 | 0.1% | Apr 7, 2026 | IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar... |
| CVE-2025-48651 | MEDIUM | 5.5 | 0.1% | Apr 6, 2026 | In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr... |
| CVE-2025-61166 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted ... |
| CVE-2025-47374 | MEDIUM | 6.5 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling. |
| CVE-2025-14938 | MEDIUM | 5.3 | 0.3% | Apr 4, 2026 | The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ... |
| CVE-2025-15064 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-13368 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P... |
| CVE-2025-68153 | MEDIUM | 6.5 | 0.2% | Apr 3, 2026 | Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ... |
| CVE-2025-68152 | MEDIUM | 4.9 | 0.4% | Apr 3, 2026 | Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ... |
| CVE-2025-59709 | MEDIUM | 6.8 | 0.9% | Apr 3, 2026 | An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b... |
| CVE-2025-43238 | MEDIUM | 6.2 | 0.2% | Apr 2, 2026 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonom... |
| CVE-2025-43210 | MEDIUM | 6.3 | 0.4% | Apr 2, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18... |
| CVE-2025-66487 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em... |
| CVE-2025-66486 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-66485 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by... |
| CVE-2025-66484 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2025-66483 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic... |
| CVE-2025-36373 | MEDIUM | 6.8 | 0.3% | Apr 1, 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I... |
| CVE-2025-66442 | MEDIUM | 5.1 | 0.3% | Apr 1, 2026 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ... |
| CVE-2025-67807 | MEDIUM | 4.7 | 0.1% | Apr 1, 2026 | The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer... |
| CVE-2025-67806 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer... |
| CVE-2025-13535 | MEDIUM | 6.4 | 0.2% | Apr 1, 2026 | The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc... |
| CVE-2025-71280 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu... |
| CVE-2025-41357 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now