2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60889 | CRITICAL | 9.8 | 0.5% | Apr 28, 2026 | Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e... |
| CVE-2025-60887 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m... |
| CVE-2025-67223 | HIGH | 7.5 | 0.6% | Apr 28, 2026 | The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w... |
| CVE-2025-48431 | HIGH | 7.5 | 1.1% | Apr 28, 2026 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apach... |
| CVE-2025-10539 | MEDIUM | 4.8 | 0.2% | Apr 28, 2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p... |
| CVE-2025-69428 | HIGH | 7.5 | 0.3% | Apr 27, 2026 | An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi... |
| CVE-2025-69689 | HIGH | 8.8 | 0.1% | Apr 27, 2026 | The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dial... |
| CVE-2025-54505 | LOW | 2 | 0.2% | Apr 27, 2026 | A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa... |
| CVE-2025-15626 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application |
| CVE-2025-67259 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user... |
| CVE-2025-59308 | MEDIUM | 4.7 | 0.2% | Apr 24, 2026 | In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ... |
| CVE-2025-61872 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer... |
| CVE-2025-62233 | MEDIUM | 6.3 | 0.5% | Apr 24, 2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi... |
| CVE-2025-11762 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2025-62373 | CRITICAL | 9.8 | 0.7% | Apr 23, 2026 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0... |
| CVE-2025-50229 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. |
| CVE-2025-70994 | HIGH | 7.3 | 0.3% | Apr 23, 2026 | Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent... |
| CVE-2025-66286 | MEDIUM | 4.7 | 0.2% | Apr 23, 2026 | An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ... |
| CVE-2025-13763 | MEDIUM | 5.7 | 0.2% | Apr 23, 2026 | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ... |
| CVE-2025-62110 | MEDIUM | 6.5 | 0.1% | Apr 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc... |
| CVE-2025-62104 | MEDIUM | 4.3 | 0.2% | Apr 23, 2026 | Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-10549 | MEDIUM | 5.1 | 0.2% | Apr 23, 2026 | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in... |
| CVE-2025-36074 | HIGH | 7.2 | 0.3% | Apr 23, 2026 | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m... |
| CVE-2025-9957 | LOW | 2.7 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-6016 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now