2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4537 | LOW | 3.1 | 0.2% | May 11, 2025 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue i... |
| CVE-2025-47736 | LOW | 2.9 | 0.2% | May 9, 2025 | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v... |
| CVE-2025-46812 | LOW | 2 | 0.6% | May 8, 2025 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to... |
| CVE-2025-46712 | LOW | 3.7 | 0.4% | May 8, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-... |
| CVE-2025-44021 | LOW | 2.8 | 0.1% | May 8, 2025 | OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w... |
| CVE-2025-46826 | LOW | 1.3 | 0.4% | May 7, 2025 | insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's ... |
| CVE-2025-46824 | LOW | 3.1 | 0.3% | May 7, 2025 | The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacke... |
| CVE-2025-46551 | LOW | 3.7 | 0.2% | May 7, 2025 | JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio... |
| CVE-2025-20977 | LOW | 3.3 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc... |
| CVE-2025-20960 | LOW | 3.3 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attacker... |
| CVE-2025-1400 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers... |
| CVE-2025-1399 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff... |
| CVE-2025-46735 | LOW | 1.1 | 0.6% | May 6, 2025 | Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue ... |
| CVE-2025-2545 | LOW | 2.3 | 0.2% | May 5, 2025 | Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptograp... |
| CVE-2025-4215 | LOW | 3.7 | 0.5% | May 2, 2025 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t... |
| CVE-2025-47226 | LOW | 3.3 | 1.1% | May 2, 2025 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. |
| CVE-2025-3514 | LOW | 3.5 | 0.2% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3513 | LOW | 3.5 | 0.3% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-32971 | LOW | 3.8 | 0.3% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4,... |
| CVE-2025-3301 | LOW | 1 | 0.2% | Apr 29, 2025 | DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on al... |
| CVE-2025-46330 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat... |
| CVE-2025-46329 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to... |
| CVE-2025-46614 | LOW | 3.3 | 0.1% | Apr 28, 2025 | In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a... |
| CVE-2025-23377 | LOW | 3.4 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output ... |
| CVE-2025-32471 | LOW | 3.7 | 0.3% | Apr 28, 2025 | The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now