2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51414 | HIGH | 8.8 | 0.3% | Apr 13, 2026 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ... |
| CVE-2025-3756 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li... |
| CVE-2025-69627 | HIGH | 8.4 | 0.2% | Apr 13, 2026 | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript... |
| CVE-2025-69624 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio... |
| CVE-2025-66769 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-63743 | MEDIUM | 5.4 | 0.3% | Apr 13, 2026 | Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a... |
| CVE-2025-31991 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut... |
| CVE-2025-66236 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate ... |
| CVE-2025-15632 | LOW | 3.5 | 0.3% | Apr 13, 2026 | A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.... |
| CVE-2025-15441 | MEDIUM | 6.8 | 0.3% | Apr 13, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ... |
| CVE-2025-66447 | MEDIUM | 4.7 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ... |
| CVE-2025-44560 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. |
| CVE-2025-5804 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58920 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato... |
| CVE-2025-58913 | HIGH | 8.1 | 0.5% | Apr 10, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-14545 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ... |
| CVE-2025-59969 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolki... |
| CVE-2025-13914 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a... |
| CVE-2025-13926 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request... |
| CVE-2025-70797 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-63238 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio... |
| CVE-2025-70365 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup... |
| CVE-2025-70364 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP cod... |
| CVE-2025-15480 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i... |
| CVE-2025-14551 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation fai... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now