2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3922 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-0186 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2025-58922 | MEDIUM | 4.3 | 0.1% | Apr 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect... |
| CVE-2025-70420 | — | — | — | Apr 21, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-41029 | CRITICAL | 9.3 | 0.2% | Apr 21, 2026 | SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ... |
| CVE-2025-41011 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic... |
| CVE-2025-15638 | CRITICAL | 10 | 0.6% | Apr 21, 2026 | Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before... |
| CVE-2025-31981 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al... |
| CVE-2025-31958 | HIGH | 8.2 | 0.2% | Apr 21, 2026 | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh... |
| CVE-2025-1241 | MEDIUM | 4.9 | 0.1% | Apr 21, 2026 | Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize... |
| CVE-2025-14362 | HIGH | 7.3 | 0.2% | Apr 21, 2026 | The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin... |
| CVE-2025-10354 | MEDIUM | 5.1 | 0.3% | Apr 21, 2026 | Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu... |
| CVE-2025-13826 | HIGH | 8.2 | 0.3% | Apr 21, 2026 | Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu... |
| CVE-2025-11249 | — | — | — | Apr 20, 2026 | Rejected reason: This CVE id was assigned as a duplicate of CVE-2025-66414. |
| CVE-2025-66954 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to... |
| CVE-2025-66335 | MEDIUM | 5.3 | 0.7% | Apr 20, 2026 | Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han... |
| CVE-2025-13480 | MEDIUM | 6.5 | 0.3% | Apr 20, 2026 | Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re... |
| CVE-2025-65104 | HIGH | 7.5 | 0.2% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect... |
| CVE-2025-70795 | MEDIUM | 5.5 | 0.2% | Apr 17, 2026 | STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT... |
| CVE-2025-46641 | MEDIUM | 6.6 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46607 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46606 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-46605 | HIGH | 7.2 | 0.3% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont... |
| CVE-2025-36568 | HIGH | 7.8 | 0.1% | Apr 17, 2026 | Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio... |
| CVE-2025-15625 | CRITICAL | 9.8 | 0.4% | Apr 17, 2026 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now