2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14688 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-56568 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Functi... |
| CVE-2025-46115 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification... |
| CVE-2025-71284 | CRITICAL | 9.8 | 5.7% | Apr 30, 2026 | Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi... |
| CVE-2025-51846 | HIGH | 8.7 | 0.6% | Apr 30, 2026 | CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o... |
| CVE-2025-51850 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-51849 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-51847 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-14543 | CRITICAL | 9.1 | 0.2% | Apr 30, 2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ... |
| CVE-2025-13890 | — | — | — | Apr 30, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a ... |
| CVE-2025-14576 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio... |
| CVE-2025-13030 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ... |
| CVE-2025-50328 | HIGH | 7.3 | 0.3% | Apr 29, 2026 | A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th... |
| CVE-2025-56537 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute... |
| CVE-2025-56536 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri... |
| CVE-2025-56535 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2025-56534 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t... |
| CVE-2025-10503 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ... |
| CVE-2025-60889 | CRITICAL | 9.8 | 0.5% | Apr 28, 2026 | Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e... |
| CVE-2025-60887 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m... |
| CVE-2025-67223 | HIGH | 7.5 | 0.6% | Apr 28, 2026 | The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w... |
| CVE-2025-48431 | HIGH | 7.5 | 1.1% | Apr 28, 2026 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach... |
| CVE-2025-10539 | MEDIUM | 4.8 | 0.2% | Apr 28, 2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p... |
| CVE-2025-69428 | HIGH | 7.5 | 0.3% | Apr 27, 2026 | An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi... |
| CVE-2025-69689 | HIGH | 8.8 | 0.1% | Apr 27, 2026 | The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now