2025 CVE Vulnerabilities
45,187 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4072 | HIGH | 8.8 | 0.4% | Apr 29, 2025 | A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects so... |
| CVE-2025-45956 | HIGH | 8.8 | 0.4% | Apr 29, 2025 | A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows a... |
| CVE-2025-23181 | HIGH | 8 | 0.3% | Apr 29, 2025 | CWE-250: Execution with Unnecessary Privileges |
| CVE-2025-23180 | HIGH | 8 | 0.3% | Apr 29, 2025 | CWE-250: Execution with Unnecessary Privileges |
| CVE-2025-4069 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affect... |
| CVE-2025-4068 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by th... |
| CVE-2025-40619 | HIGH | 7.5 | 0.3% | Apr 29, 2025 | Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could all... |
| CVE-2025-32354 | HIGH | 8.8 | 0.3% | Apr 29, 2025 | In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL ... |
| CVE-2025-23178 | HIGH | 7.6 | 0.2% | Apr 29, 2025 | CWE-923: Improper Restriction of Communication Channel to Intended Endpoints |
| CVE-2025-23177 | HIGH | 7.6 | 0.2% | Apr 29, 2025 | CWE-427: Uncontrolled Search Path Element |
| CVE-2025-4065 | HIGH | 7.5 | 0.4% | Apr 29, 2025 | A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerabi... |
| CVE-2025-4093 | HIGH | 8.1 | 0.4% | Apr 29, 2025 | Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and... |
| CVE-2025-4091 | HIGH | 8.1 | 0.4% | Apr 29, 2025 | Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs... |
| CVE-2025-4085 | HIGH | 7.1 | 0.2% | Apr 29, 2025 | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive... |
| CVE-2025-4063 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affecte... |
| CVE-2025-4062 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by ... |
| CVE-2025-2817 | HIGH | 8.8 | 0.5% | Apr 29, 2025 | Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man... |
| CVE-2025-4061 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0... |
| CVE-2025-4059 | HIGH | 7.8 | 0.3% | Apr 29, 2025 | A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affec... |
| CVE-2025-3891 | HIGH | 7.5 | 1.2% | Apr 29, 2025 | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to... |
| CVE-2025-30194 | HIGH | 7.5 | 2.0% | Apr 29, 2025 | When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by craftin... |
| CVE-2025-24252 | HIGH | 8.8 | 1.3% | Apr 29, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i... |
| CVE-2025-24206 | HIGH | 7.7 | 0.3% | Apr 29, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i... |
| CVE-2025-46328 | HIGH | 7 | 0.1% | Apr 28, 2025 | snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerab... |
| CVE-2025-46327 | HIGH | 7 | 0.1% | Apr 28, 2025 | gosnowflake is the Snowflake Golang driver. Versions starting from 1.7.0 to before 1.13.3, are vulnerable to a Time-of-C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now