2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46232 | HIGH | 8.8 | 0.2% | Apr 22, 2025 | Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configure... |
| CVE-2025-46231 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter... |
| CVE-2025-3519 | HIGH | 7 | 0.2% | Apr 22, 2025 | An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Ev... |
| CVE-2025-26413 | HIGH | 7.5 | 0.6% | Apr 22, 2025 | Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a... |
| CVE-2025-2594 | HIGH | 8.1 | 7.2% | Apr 22, 2025 | The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when ... |
| CVE-2025-3616 | HIGH | 8.8 | 2.0% | Apr 22, 2025 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m... |
| CVE-2025-1731 | HIGH | 7.8 | 0.9% | Apr 22, 2025 | An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware ... |
| CVE-2025-3854 | HIGH | 8.6 | 0.5% | Apr 22, 2025 | A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E... |
| CVE-2025-32956 | HIGH | 8 | 0.5% | Apr 21, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ... |
| CVE-2025-27086 | HIGH | 8.1 | 0.3% | Apr 21, 2025 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. |
| CVE-2025-23174 | HIGH | 7.5 | 0.3% | Apr 21, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-43922 | HIGH | 8.1 | 0.1% | Apr 21, 2025 | The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca... |
| CVE-2025-3857 | HIGH | 8.7 | 0.5% | Apr 21, 2025 | When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t... |
| CVE-2025-2298 | HIGH | 8.4 | 0.3% | Apr 21, 2025 | An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the... |
| CVE-2025-43972 | HIGH | 7.5 | 0.5% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec pars... |
| CVE-2025-43971 | HIGH | 7.5 | 0.5% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value... |
| CVE-2025-43967 | HIGH | 7.5 | 0.4% | Apr 21, 2025 | libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a gri... |
| CVE-2025-43966 | HIGH | 7.5 | 0.3% | Apr 21, 2025 | libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc. |
| CVE-2025-43929 | HIGH | 7.8 | 0.2% | Apr 20, 2025 | open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that ma... |
| CVE-2025-43920 | HIGH | 8.1 | 0.5% | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated ... |
| CVE-2025-43919 | HIGH | 7.5 | 1.4% | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ dir... |
| CVE-2025-3820 | HIGH | 8.8 | 8.1% | Apr 19, 2025 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this ... |
| CVE-2025-43917 | HIGH | 8.2 | 0.1% | Apr 19, 2025 | In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst... |
| CVE-2025-3817 | HIGH | 8.8 | 0.4% | Apr 19, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue ... |
| CVE-2025-3816 | HIGH | 7.2 | 5.9% | Apr 19, 2025 | A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now