2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31489 | HIGH | 8.7 | 2.3% | Apr 3, 2025 | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature componen... |
| CVE-2025-31485 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL g... |
| CVE-2025-31481 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you c... |
| CVE-2025-31119 | HIGH | 7.6 | 0.5% | Apr 3, 2025 | generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generato... |
| CVE-2025-29570 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t... |
| CVE-2025-29504 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm... |
| CVE-2025-31487 | HIGH | 7.7 | 0.3% | Apr 3, 2025 | The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If th... |
| CVE-2025-3167 | HIGH | 7.5 | 0.7% | Apr 3, 2025 | A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some ... |
| CVE-2025-3166 | HIGH | 7.8 | 0.3% | Apr 3, 2025 | A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affe... |
| CVE-2025-31115 | HIGH | 8.7 | 0.6% | Apr 3, 2025 | XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, th... |
| CVE-2025-3163 | HIGH | 7.8 | 0.3% | Apr 3, 2025 | A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerabi... |
| CVE-2025-29987 | HIGH | 8.8 | 0.5% | Apr 3, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficie... |
| CVE-2025-3162 | HIGH | 7.8 | 0.3% | Apr 3, 2025 | A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function... |
| CVE-2025-3161 | HIGH | 8.8 | 0.8% | Apr 3, 2025 | A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function Shutdown... |
| CVE-2025-0272 | HIGH | 7.6 | 0.2% | Apr 3, 2025 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H... |
| CVE-2025-3159 | HIGH | 7.8 | 0.3% | Apr 3, 2025 | A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the... |
| CVE-2025-3158 | HIGH | 7.8 | 0.3% | Apr 3, 2025 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by... |
| CVE-2025-3155 | HIGH | 7.4 | 10.6% | Apr 3, 2025 | A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vu... |
| CVE-2025-32049 | HIGH | 7.5 | 0.7% | Apr 3, 2025 | A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup t... |
| CVE-2025-31909 | HIGH | 7.5 | 0.3% | Apr 3, 2025 | Missing Authorization vulnerability in Apptivo Apptivo Business Site CRM apptivo-business-site allows Exploiting Incorre... |
| CVE-2025-31907 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team B... |
| CVE-2025-31905 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O'Donnell Tea... |
| CVE-2025-31903 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xavi Ivars XV Rand... |
| CVE-2025-31902 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ... |
| CVE-2025-31901 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digihood Digihood ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now