2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0627 | LOW | 3.5 | 0.2% | Apr 28, 2025 | The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i... |
| CVE-2025-3995 | LOW | 3.4 | 0.4% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vuln... |
| CVE-2025-3994 | LOW | 3.4 | 4.0% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unkn... |
| CVE-2025-46656 | LOW | 3.3 | 0.2% | Apr 26, 2025 | python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>... |
| CVE-2025-46653 | LOW | 3.1 | 0.4% | Apr 26, 2025 | Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un... |
| CVE-2025-3637 | LOW | 3.1 | 0.3% | Apr 25, 2025 | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CS... |
| CVE-2025-3635 | LOW | 3.5 | 0.2% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log ... |
| CVE-2025-25046 | LOW | 3.7 | 0.1% | Apr 23, 2025 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parame... |
| CVE-2025-46394 | LOW | 3.3 | 0.1% | Apr 23, 2025 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc... |
| CVE-2025-23253 | LOW | 2.5 | 0.1% | Apr 22, 2025 | NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit... |
| CVE-2025-27907 | LOW | 2.7 | 0.3% | Apr 22, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an auth... |
| CVE-2025-3850 | LOW | 2.7 | 0.5% | Apr 22, 2025 | A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu... |
| CVE-2025-2517 | LOW | 2.3 | 0.4% | Apr 21, 2025 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. |
| CVE-2025-43916 | LOW | 3.4 | 0.2% | Apr 21, 2025 | Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use... |
| CVE-2025-32408 | LOW | 2.5 | 0.1% | Apr 21, 2025 | In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled. |
| CVE-2025-3840 | LOW | 2.1 | 0.2% | Apr 21, 2025 | An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer co... |
| CVE-2025-25228 | LOW | 3.8 | 0.2% | Apr 21, 2025 | A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu... |
| CVE-2025-43903 | LOW | 3.3 | 0.1% | Apr 18, 2025 | NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting... |
| CVE-2025-3795 | LOW | 3.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun... |
| CVE-2025-25985 | LOW | 2.6 | 0.3% | Apr 18, 2025 | An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim... |
| CVE-2025-25983 | LOW | 3.4 | 0.3% | Apr 18, 2025 | An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64... |
| CVE-2025-1525 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-1524 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-1523 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-32789 | LOW | 3.7 | 0.3% | Apr 16, 2025 | EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now