2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71310 | LOW | 1.8 | 0.3% | May 26, 2026 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scri... |
| CVE-2025-14575 | LOW | 1.8 | 0.1% | May 19, 2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (... |
| CVE-2025-52532 | LOW | 2 | 0.1% | May 15, 2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa... |
| CVE-2025-66660 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2025-62317 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive... |
| CVE-2025-62316 | LOW | 2.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured... |
| CVE-2025-62312 | LOW | 3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho... |
| CVE-2025-62309 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may ... |
| CVE-2025-31959 | LOW | 3.5 | 0.1% | May 6, 2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co... |
| CVE-2025-62345 | LOW | 2.7 | 0.2% | May 6, 2026 | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con... |
| CVE-2025-54505 | LOW | 2 | 0.2% | Apr 27, 2026 | A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa... |
| CVE-2025-9957 | LOW | 2.7 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-15632 | LOW | 3.5 | 0.3% | Apr 13, 2026 | A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.... |
| CVE-2025-43236 | LOW | 3.3 | 0.2% | Apr 2, 2026 | A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son... |
| CVE-2025-62184 | LOW | 3.4 | 0.3% | Mar 31, 2026 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf... |
| CVE-2025-7741 | LOW | 2.1 | 0.2% | Mar 30, 2026 | Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ... |
| CVE-2025-14684 | LOW | 3.3 | 0.1% | Mar 25, 2026 | IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat... |
| CVE-2025-14808 | LOW | 3.1 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from... |
| CVE-2025-11571 | LOW | 2.1 | 0.4% | Mar 24, 2026 | Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm... |
| CVE-2025-31703 | LOW | 2.4 | 0.2% | Mar 18, 2026 | A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may g... |
| CVE-2025-31966 | LOW | 2.7 | 0.2% | Mar 17, 2026 | HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th... |
| CVE-2025-69239 | LOW | 2.7 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker... |
| CVE-2025-26474 | LOW | 3.3 | 0.1% | Mar 16, 2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can... |
| CVE-2025-13462 | LOW | 3.3 | 0.2% | Mar 12, 2026 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi... |
| CVE-2025-62328 | LOW | 3.7 | 0.2% | Mar 11, 2026 | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by defa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now