2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54550 | HIGH | 8.1 | 0.6% | Apr 15, 2026 | The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco... |
| CVE-2025-61848 | HIGH | 7.2 | 0.5% | Apr 14, 2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA... |
| CVE-2025-53847 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro... |
| CVE-2025-7389 | HIGH | 8.2 | 0.3% | Apr 14, 2026 | A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le... |
| CVE-2025-51414 | HIGH | 8.8 | 0.3% | Apr 13, 2026 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ... |
| CVE-2025-3756 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li... |
| CVE-2025-69627 | HIGH | 8.4 | 0.2% | Apr 13, 2026 | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript... |
| CVE-2025-69624 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio... |
| CVE-2025-66769 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-66236 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ... |
| CVE-2025-5804 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58920 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato... |
| CVE-2025-58913 | HIGH | 8.1 | 0.5% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59969 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki... |
| CVE-2025-13914 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a... |
| CVE-2025-70364 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod... |
| CVE-2025-14551 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai... |
| CVE-2025-70810 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-62188 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vul... |
| CVE-2025-12664 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 1... |
| CVE-2025-50673 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport paramet... |
| CVE-2025-50672 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_... |
| CVE-2025-50671 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_... |
| CVE-2025-50670 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_... |
| CVE-2025-50669 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now