2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3160 | LOW | 3.3 | 0.2% | Apr 3, 2025 | A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerabili... |
| CVE-2025-29991 | LOW | 2.2 | 0.1% | Apr 3, 2025 | Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It u... |
| CVE-2025-3154 | LOW | 2.1 | 0.1% | Apr 2, 2025 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictio... |
| CVE-2025-27608 | LOW | 1 | 0.2% | Apr 2, 2025 | Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vu... |
| CVE-2025-30469 | LOW | 2.4 | 0.2% | Mar 31, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person wi... |
| CVE-2025-24193 | LOW | 2.4 | 0.5% | Mar 31, 2025 | This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with... |
| CVE-2025-30369 | LOW | 2.7 | 0.2% | Mar 31, 2025 | Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed t... |
| CVE-2025-30368 | LOW | 2.7 | 0.3% | Mar 31, 2025 | Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricte... |
| CVE-2025-27149 | LOW | 2.7 | 0.3% | Mar 31, 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data exp... |
| CVE-2025-1217 | LOW | 3.1 | 0.5% | Mar 29, 2025 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http ... |
| CVE-2025-2923 | LOW | 3.3 | 0.2% | Mar 28, 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the... |
| CVE-2025-2922 | LOW | 2 | 0.1% | Mar 28, 2025 | A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unk... |
| CVE-2025-2920 | LOW | 2 | 0.1% | Mar 28, 2025 | A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown ... |
| CVE-2025-2914 | LOW | 3.3 | 0.2% | Mar 28, 2025 | A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Sri... |
| CVE-2025-30371 | LOW | 2.1 | 0.4% | Mar 28, 2025 | Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and ... |
| CVE-2025-27726 | LOW | 2.1 | 0.2% | Mar 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process... |
| CVE-2025-27574 | LOW | 3.6 | 0.2% | Mar 28, 2025 | Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and e... |
| CVE-2025-30877 | LOW | 2.7 | 0.4% | Mar 27, 2025 | Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-20233 | LOW | 3.3 | 0.1% | Mar 26, 2025 | In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Pyth... |
| CVE-2025-31160 | LOW | 2.9 | 0.2% | Mar 26, 2025 | atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or po... |
| CVE-2025-2528 | LOW | 3.6 | 0.2% | Mar 26, 2025 | Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authent... |
| CVE-2025-24808 | LOW | 3.1 | 0.2% | Mar 26, 2025 | Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t... |
| CVE-2025-30222 | LOW | 2.1 | 0.2% | Mar 25, 2025 | Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential envir... |
| CVE-2025-1452 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2025-0717 | LOW | 3.5 | 0.2% | Mar 25, 2025 | To exploit the vulnerability, it is necessary: |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now