2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70072 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:... |
| CVE-2025-70070 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet... |
| CVE-2025-14726 | MEDIUM | 6.5 | 0.8% | May 2, 2026 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ... |
| CVE-2025-69606 | MEDIUM | 6.1 | 0.4% | May 1, 2026 | Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t... |
| CVE-2025-36335 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo... |
| CVE-2025-36122 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could... |
| CVE-2025-14688 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-56537 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute... |
| CVE-2025-56536 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri... |
| CVE-2025-56535 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2025-56534 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t... |
| CVE-2025-10503 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ... |
| CVE-2025-60887 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m... |
| CVE-2025-10539 | MEDIUM | 4.8 | 0.2% | Apr 28, 2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p... |
| CVE-2025-15626 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application |
| CVE-2025-67259 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user... |
| CVE-2025-59308 | MEDIUM | 4.7 | 0.2% | Apr 24, 2026 | In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ... |
| CVE-2025-61872 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer... |
| CVE-2025-62233 | MEDIUM | 6.3 | 0.5% | Apr 24, 2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi... |
| CVE-2025-11762 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2025-66286 | MEDIUM | 4.7 | 0.2% | Apr 23, 2026 | An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ... |
| CVE-2025-13763 | MEDIUM | 5.7 | 0.2% | Apr 23, 2026 | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ... |
| CVE-2025-62110 | MEDIUM | 6.5 | 0.1% | Apr 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc... |
| CVE-2025-62104 | MEDIUM | 4.3 | 0.2% | Apr 23, 2026 | Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-10549 | MEDIUM | 5.1 | 0.2% | Apr 23, 2026 | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now