2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3142 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This... |
| CVE-2025-3139 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-3134 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an un... |
| CVE-2025-3123 | HIGH | 7.2 | 0.5% | Apr 2, 2025 | A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the func... |
| CVE-2025-31479 | HIGH | 8.2 | 0.5% | Apr 2, 2025 | canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workfl... |
| CVE-2025-0257 | HIGH | 7.5 | 0.3% | Apr 2, 2025 | HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data... |
| CVE-2025-30080 | HIGH | 7.5 | 0.5% | Apr 2, 2025 | Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t... |
| CVE-2025-2704 | HIGH | 7.5 | 0.8% | Apr 2, 2025 | OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of se... |
| CVE-2025-22925 | HIGH | 7.5 | 0.4% | Apr 2, 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendanc... |
| CVE-2025-22924 | HIGH | 8.8 | 0.4% | Apr 2, 2025 | OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Stu... |
| CVE-2025-22923 | HIGH | 8.8 | 0.8% | Apr 2, 2025 | An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sendin... |
| CVE-2025-31285 | HIGH | 7.2 | 0.2% | Apr 2, 2025 | A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allow... |
| CVE-2025-31284 | HIGH | 7.2 | 0.2% | Apr 2, 2025 | A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed ... |
| CVE-2025-31283 | HIGH | 7.2 | 0.2% | Apr 2, 2025 | A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allo... |
| CVE-2025-31282 | HIGH | 7.2 | 0.2% | Apr 2, 2025 | A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have al... |
| CVE-2025-20212 | HIGH | 7.7 | 0.7% | Apr 2, 2025 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an a... |
| CVE-2025-20139 | HIGH | 7.5 | 0.6% | Apr 2, 2025 | A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo... |
| CVE-2025-0014 | HIGH | 7.3 | 0.2% | Apr 2, 2025 | Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege e... |
| CVE-2025-0154 | HIGH | 7.5 | 0.4% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper n... |
| CVE-2025-31722 | HIGH | 8.8 | 1.1% | Apr 2, 2025 | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protectio... |
| CVE-2025-30090 | HIGH | 7.2 | 0.2% | Apr 2, 2025 | mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers,... |
| CVE-2025-27556 | HIGH | 7.5 | 0.9% | Apr 2, 2025 | An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As ... |
| CVE-2025-21993 | HIGH | 7.1 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: iscsi_ibft: Fix UBSAN shift-out-of-bounds warning i... |
| CVE-2025-21991 | HIGH | 7.8 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix out-of-bounds on systems wit... |
| CVE-2025-3063 | HIGH | 8.8 | 0.4% | Apr 2, 2025 | The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now