2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31981 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al... |
| CVE-2025-31958 | HIGH | 8.2 | 0.2% | Apr 21, 2026 | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh... |
| CVE-2025-1241 | MEDIUM | 4.9 | 0.1% | Apr 21, 2026 | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize... |
| CVE-2025-14362 | HIGH | 7.3 | 0.2% | Apr 21, 2026 | The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin... |
| CVE-2025-10354 | MEDIUM | 5.1 | 0.3% | Apr 21, 2026 | Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu... |
| CVE-2025-13826 | HIGH | 8.2 | 0.3% | Apr 21, 2026 | Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu... |
| CVE-2025-11249 | — | — | — | Apr 20, 2026 | Rejected reason: This CVE id was assigned as a duplicate of CVE-2025-66414. |
| CVE-2025-66954 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to... |
| CVE-2025-66335 | MEDIUM | 5.3 | 0.7% | Apr 20, 2026 | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han... |
| CVE-2025-13480 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re... |
| CVE-2025-65104 | HIGH | 7.5 | 0.2% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect... |
| CVE-2025-70795 | MEDIUM | 5.5 | 0.2% | Apr 17, 2026 | STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT... |
| CVE-2025-46641 | MEDIUM | 6.6 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46607 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46606 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46605 | HIGH | 7.2 | 0.3% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-36568 | HIGH | 7.8 | 0.1% | Apr 17, 2026 | Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio... |
| CVE-2025-15625 | CRITICAL | 9.8 | 0.4% | Apr 17, 2026 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. |
| CVE-2025-15624 | HIGH | 7.5 | 0.4% | Apr 17, 2026 | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID... |
| CVE-2025-15623 | HIGH | 7.5 | 0.3% | Apr 17, 2026 | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau... |
| CVE-2025-15622 | MEDIUM | 6.2 | 0.2% | Apr 17, 2026 | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals ... |
| CVE-2025-54502 | HIGH | 7.5 | 0.1% | Apr 16, 2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker... |
| CVE-2025-54510 | MEDIUM | 5.9 | 0.1% | Apr 16, 2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi... |
| CVE-2025-43937 | MEDIUM | 6.6 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab... |
| CVE-2025-43935 | MEDIUM | 4.4 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now