2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43210 | MEDIUM | 6.3 | 0.4% | Apr 2, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18... |
| CVE-2025-43202 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1... |
| CVE-2025-65114 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Se... |
| CVE-2025-58136 | HIGH | 7.5 | 0.7% | Apr 2, 2026 | A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from... |
| CVE-2025-66487 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em... |
| CVE-2025-66486 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-66485 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by... |
| CVE-2025-66484 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2025-66483 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic... |
| CVE-2025-36375 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I... |
| CVE-2025-0711 | — | — | — | Apr 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-36373 | MEDIUM | 6.8 | 0.3% | Apr 1, 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I... |
| CVE-2025-13916 | HIGH | 7.5 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t... |
| CVE-2025-66442 | MEDIUM | 5.1 | 0.3% | Apr 1, 2026 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ... |
| CVE-2025-67807 | MEDIUM | 4.7 | 0.1% | Apr 1, 2026 | The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer... |
| CVE-2025-67806 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer... |
| CVE-2025-67805 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat... |
| CVE-2025-13535 | MEDIUM | 6.4 | 0.2% | Apr 1, 2026 | The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc... |
| CVE-2025-15484 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant... |
| CVE-2025-71282 | HIGH | 8.7 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ... |
| CVE-2025-71281 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in... |
| CVE-2025-71280 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu... |
| CVE-2025-71279 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may... |
| CVE-2025-71278 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O... |
| CVE-2025-13855 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now