2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6016 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ... |
| CVE-2025-3922 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-0186 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-58922 | MEDIUM | 4.3 | 0.1% | Apr 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect... |
| CVE-2025-41011 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic... |
| CVE-2025-31981 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al... |
| CVE-2025-1241 | MEDIUM | 4.9 | 0.1% | Apr 21, 2026 | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize... |
| CVE-2025-10354 | MEDIUM | 5.1 | 0.3% | Apr 21, 2026 | Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu... |
| CVE-2025-66954 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to... |
| CVE-2025-66335 | MEDIUM | 5.3 | 0.7% | Apr 20, 2026 | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han... |
| CVE-2025-13480 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re... |
| CVE-2025-70795 | MEDIUM | 5.5 | 0.2% | Apr 17, 2026 | STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT... |
| CVE-2025-46641 | MEDIUM | 6.6 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-15622 | MEDIUM | 6.2 | 0.2% | Apr 17, 2026 | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals ... |
| CVE-2025-54510 | MEDIUM | 5.9 | 0.1% | Apr 16, 2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi... |
| CVE-2025-43937 | MEDIUM | 6.6 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab... |
| CVE-2025-43935 | MEDIUM | 4.4 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi... |
| CVE-2025-43883 | MEDIUM | 4.1 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln... |
| CVE-2025-36579 | MEDIUM | 5.1 | 0.2% | Apr 16, 2026 | Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph... |
| CVE-2025-15621 | MEDIUM | 6 | 0.1% | Apr 16, 2026 | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re... |
| CVE-2025-12624 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail... |
| CVE-2025-6024 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script... |
| CVE-2025-13364 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2025-15636 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You... |
| CVE-2025-15635 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now