2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66236 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ... |
| CVE-2025-15632 | LOW | 3.5 | 0.3% | Apr 13, 2026 | A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.... |
| CVE-2025-15441 | MEDIUM | 6.8 | 0.3% | Apr 13, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ... |
| CVE-2025-66447 | MEDIUM | 4.7 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ... |
| CVE-2025-44560 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. |
| CVE-2025-5804 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58920 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato... |
| CVE-2025-58913 | HIGH | 8.1 | 0.5% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-14545 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ... |
| CVE-2025-59969 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki... |
| CVE-2025-13914 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a... |
| CVE-2025-13926 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request... |
| CVE-2025-70797 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-63238 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio... |
| CVE-2025-70365 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup... |
| CVE-2025-70364 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod... |
| CVE-2025-15480 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i... |
| CVE-2025-14551 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai... |
| CVE-2025-70811 | MEDIUM | 4.3 | 0.1% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-70810 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-62718 | CRITICAL | 9.9 | 1.2% | Apr 9, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h... |
| CVE-2025-50228 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. |
| CVE-2025-45806 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar... |
| CVE-2025-57735 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t... |
| CVE-2025-62188 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now