2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43883 | MEDIUM | 4.1 | 0.1% | Apr 16, 2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln... |
| CVE-2025-36579 | MEDIUM | 5.1 | 0.2% | Apr 16, 2026 | Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph... |
| CVE-2025-15621 | MEDIUM | 5.7 | 0.1% | Apr 16, 2026 | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re... |
| CVE-2025-12624 | MEDIUM | 5.4 | 0.2% | Apr 16, 2026 | Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail... |
| CVE-2025-6024 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script... |
| CVE-2025-14868 | HIGH | 8.8 | 0.4% | Apr 16, 2026 | The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr... |
| CVE-2025-13364 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2025-41118 | CRITICAL | 9.1 | 0.4% | Apr 15, 2026 | Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten... |
| CVE-2025-63029 | HIGH | 7.6 | 0.3% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar... |
| CVE-2025-15636 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You... |
| CVE-2025-15635 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro... |
| CVE-2025-15610 | CRITICAL | 9.3 | 0.3% | Apr 15, 2026 | The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi... |
| CVE-2025-67841 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue. |
| CVE-2025-53444 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i... |
| CVE-2025-12141 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif... |
| CVE-2025-14813 | CRITICAL | 9.3 | 0.3% | Apr 15, 2026 | : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a... |
| CVE-2025-52641 | MEDIUM | 5.3 | 0.1% | Apr 15, 2026 | HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str... |
| CVE-2025-40899 | HIGH | 8.9 | 0.3% | Apr 15, 2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat... |
| CVE-2025-40897 | HIGH | 8.1 | 0.3% | Apr 15, 2026 | An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric... |
| CVE-2025-54550 | HIGH | 8.1 | 0.6% | Apr 15, 2026 | The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco... |
| CVE-2025-15470 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th... |
| CVE-2025-15565 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check... |
| CVE-2025-70023 | CRITICAL | 9.8 | 0.4% | Apr 14, 2026 | An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. |
| CVE-2025-68649 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze... |
| CVE-2025-65136 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now