2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40897 | HIGH | 8.1 | 0.3% | Apr 15, 2026 | An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric... |
| CVE-2025-54550 | HIGH | 8.1 | 0.6% | Apr 15, 2026 | The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco... |
| CVE-2025-15470 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th... |
| CVE-2025-15565 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check... |
| CVE-2025-70023 | CRITICAL | 9.8 | 0.4% | Apr 14, 2026 | An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. |
| CVE-2025-68649 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze... |
| CVE-2025-65136 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v... |
| CVE-2025-65135 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin... |
| CVE-2025-65134 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms... |
| CVE-2025-65133 | CRITICAL | 9.8 | 0.5% | Apr 14, 2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ... |
| CVE-2025-65132 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a... |
| CVE-2025-63939 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al... |
| CVE-2025-61886 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-61848 | HIGH | 7.2 | 0.5% | Apr 14, 2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA... |
| CVE-2025-61624 | MEDIUM | 6.5 | 0.5% | Apr 14, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For... |
| CVE-2025-59809 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P... |
| CVE-2025-53847 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro... |
| CVE-2025-69993 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This... |
| CVE-2025-69893 | MEDIUM | 4.6 | 0.2% | Apr 14, 2026 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13... |
| CVE-2025-61260 | CRITICAL | 9.8 | 7.1% | Apr 14, 2026 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ... |
| CVE-2025-8095 | CRITICAL | 9.1 | 0.2% | Apr 14, 2026 | The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as crypt... |
| CVE-2025-7389 | HIGH | 8.2 | 0.3% | Apr 14, 2026 | A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le... |
| CVE-2025-13822 | MEDIUM | 5.3 | 0.4% | Apr 14, 2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati... |
| CVE-2025-40745 | MEDIUM | 6.3 | 0.1% | Apr 14, 2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V... |
| CVE-2025-70936 | MEDIUM | 5.4 | 0.1% | Apr 13, 2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now