2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46826 | LOW | 1.3 | 0.4% | May 7, 2025 | insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's ... |
| CVE-2025-46824 | LOW | 3.1 | 0.3% | May 7, 2025 | The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacke... |
| CVE-2025-46551 | LOW | 3.7 | 0.2% | May 7, 2025 | JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio... |
| CVE-2025-20977 | LOW | 3.3 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc... |
| CVE-2025-20960 | LOW | 3.3 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attacker... |
| CVE-2025-1400 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers... |
| CVE-2025-1399 | LOW | 3.1 | 0.2% | May 7, 2025 | Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff... |
| CVE-2025-46735 | LOW | 1.1 | 0.6% | May 6, 2025 | Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue ... |
| CVE-2025-2545 | LOW | 2.3 | 0.2% | May 5, 2025 | Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptograp... |
| CVE-2025-4215 | LOW | 3.7 | 0.5% | May 2, 2025 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t... |
| CVE-2025-47226 | LOW | 3.3 | 1.1% | May 2, 2025 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. |
| CVE-2025-3514 | LOW | 3.5 | 0.2% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-3513 | LOW | 3.5 | 0.3% | May 2, 2025 | The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h... |
| CVE-2025-32971 | LOW | 3.8 | 0.3% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4,... |
| CVE-2025-3301 | LOW | 1 | 0.2% | Apr 29, 2025 | DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on al... |
| CVE-2025-46330 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat... |
| CVE-2025-46329 | LOW | 3.3 | 0.1% | Apr 29, 2025 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to... |
| CVE-2025-46614 | LOW | 3.3 | 0.1% | Apr 28, 2025 | In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a... |
| CVE-2025-23377 | LOW | 3.4 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output ... |
| CVE-2025-32471 | LOW | 3.7 | 0.3% | Apr 28, 2025 | The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks. |
| CVE-2025-0627 | LOW | 3.5 | 0.2% | Apr 28, 2025 | The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i... |
| CVE-2025-3995 | LOW | 3.4 | 0.4% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vuln... |
| CVE-2025-3994 | LOW | 3.4 | 4.0% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unkn... |
| CVE-2025-46656 | LOW | 3.3 | 0.2% | Apr 26, 2025 | python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>... |
| CVE-2025-46653 | LOW | 3.1 | 0.4% | Apr 26, 2025 | Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now