2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52347 | HIGH | 7.8 | 0.1% | May 1, 2026 | An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and Perf... |
| CVE-2025-69606 | MEDIUM | 6.1 | 0.4% | May 1, 2026 | Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t... |
| CVE-2025-63548 | HIGH | 7.5 | 0.3% | May 1, 2026 | An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet spe... |
| CVE-2025-63547 | HIGH | 7.5 | 0.4% | May 1, 2026 | An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted pa... |
| CVE-2025-36335 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo... |
| CVE-2025-36180 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow a... |
| CVE-2025-36122 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could... |
| CVE-2025-14688 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-56568 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Functi... |
| CVE-2025-46115 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification... |
| CVE-2025-71284 | CRITICAL | 9.8 | 5.7% | Apr 30, 2026 | Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi... |
| CVE-2025-51846 | HIGH | 8.7 | 0.6% | Apr 30, 2026 | CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade o... |
| CVE-2025-51850 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-51849 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-51847 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-14543 | CRITICAL | 9.1 | 0.2% | Apr 30, 2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ... |
| CVE-2025-13890 | — | — | — | Apr 30, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a ... |
| CVE-2025-14576 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio... |
| CVE-2025-13030 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ... |
| CVE-2025-50328 | HIGH | 7.3 | 0.3% | Apr 29, 2026 | A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th... |
| CVE-2025-56537 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute... |
| CVE-2025-56536 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri... |
| CVE-2025-56535 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2025-56534 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t... |
| CVE-2025-10503 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now