2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54505 | LOW | 2 | 0.2% | Apr 27, 2026 | A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa... |
| CVE-2025-15626 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application |
| CVE-2025-67259 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user... |
| CVE-2025-59308 | MEDIUM | 4.7 | 0.2% | Apr 24, 2026 | In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ... |
| CVE-2025-61872 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer... |
| CVE-2025-62233 | MEDIUM | 6.3 | 0.5% | Apr 24, 2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi... |
| CVE-2025-11762 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2025-62373 | CRITICAL | 9.8 | 0.7% | Apr 23, 2026 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0... |
| CVE-2025-50229 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. |
| CVE-2025-70994 | HIGH | 7.3 | 0.3% | Apr 23, 2026 | Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent... |
| CVE-2025-66286 | MEDIUM | 4.7 | 0.2% | Apr 23, 2026 | An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ... |
| CVE-2025-13763 | MEDIUM | 5.7 | 0.2% | Apr 23, 2026 | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ... |
| CVE-2025-62110 | MEDIUM | 6.5 | 0.1% | Apr 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc... |
| CVE-2025-62104 | MEDIUM | 4.3 | 0.2% | Apr 23, 2026 | Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-10549 | MEDIUM | 5.1 | 0.2% | Apr 23, 2026 | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in... |
| CVE-2025-36074 | HIGH | 7.2 | 0.3% | Apr 23, 2026 | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m... |
| CVE-2025-9957 | LOW | 2.7 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-6016 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ... |
| CVE-2025-3922 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-0186 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-58922 | MEDIUM | 4.3 | 0.1% | Apr 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect... |
| CVE-2025-70420 | — | — | — | Apr 21, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-41029 | CRITICAL | 9.3 | 0.2% | Apr 21, 2026 | SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ... |
| CVE-2025-41011 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic... |
| CVE-2025-15638 | CRITICAL | 10 | 0.6% | Apr 21, 2026 | Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now