2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32787 | LOW | 3.1 | 0.3% | Apr 16, 2025 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerab... |
| CVE-2025-27538 | LOW | 2.7 | 0.2% | Apr 16, 2025 | Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when ... |
| CVE-2025-32435 | LOW | 2.6 | 0.3% | Apr 15, 2025 | Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could poten... |
| CVE-2025-30731 | LOW | 3.6 | 0.1% | Apr 15, 2025 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).... |
| CVE-2025-30703 | LOW | 2.7 | 0.5% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2025-30700 | LOW | 3.5 | 0.4% | Apr 15, 2025 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The suppor... |
| CVE-2025-30681 | LOW | 2.7 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are... |
| CVE-2025-31494 | LOW | 3.5 | 0.3% | Apr 15, 2025 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-3549 | LOW | 3.3 | 0.2% | Apr 14, 2025 | A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the ... |
| CVE-2025-3548 | LOW | 3.3 | 0.2% | Apr 14, 2025 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This ... |
| CVE-2025-31362 | LOW | 3.7 | 0.2% | Apr 11, 2025 | Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtaine... |
| CVE-2025-32816 | LOW | 3.1 | 0.2% | Apr 11, 2025 | CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity. |
| CVE-2025-0124 | LOW | 3.8 | 0.3% | Apr 11, 2025 | An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacke... |
| CVE-2025-32700 | LOW | 2.3 | 0.3% | Apr 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulne... |
| CVE-2025-32699 | LOW | 2.1 | 0.3% | Apr 10, 2025 | Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.... |
| CVE-2025-32698 | LOW | 2.1 | 0.3% | Apr 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera... |
| CVE-2025-24866 | LOW | 2.7 | 0.2% | Apr 10, 2025 | Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing us... |
| CVE-2025-32382 | LOW | 1.8 | 0.3% | Apr 10, 2025 | Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection de... |
| CVE-2025-32205 | LOW | 2.7 | 0.3% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Fo... |
| CVE-2025-26479 | LOW | 3.1 | 0.2% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker cou... |
| CVE-2025-23378 | LOW | 3.3 | 0.1% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing ... |
| CVE-2025-32728 | LOW | 3.8 | 0.1% | Apr 10, 2025 | In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it dis... |
| CVE-2025-31003 | LOW | 2.7 | 0.4% | Apr 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze sq... |
| CVE-2025-27192 | LOW | 2.7 | 0.4% | Apr 8, 2025 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficien... |
| CVE-2025-3416 | LOW | 3.7 | 0.5% | Apr 8, 2025 | A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now