2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70811 | MEDIUM | 4.3 | 0.1% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-70810 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-62718 | CRITICAL | 9.9 | 1.2% | Apr 9, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h... |
| CVE-2025-50228 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. |
| CVE-2025-45806 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar... |
| CVE-2025-57735 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t... |
| CVE-2025-62188 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vul... |
| CVE-2025-9484 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.1... |
| CVE-2025-12664 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 1... |
| CVE-2025-50673 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport paramet... |
| CVE-2025-50672 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_... |
| CVE-2025-50671 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_... |
| CVE-2025-50670 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_... |
| CVE-2025-50669 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of ... |
| CVE-2025-50668 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /... |
| CVE-2025-50667 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in t... |
| CVE-2025-50666 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in t... |
| CVE-2025-50665 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the ... |
| CVE-2025-50664 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_... |
| CVE-2025-50663 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in th... |
| CVE-2025-50662 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in th... |
| CVE-2025-50661 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in t... |
| CVE-2025-50660 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in th... |
| CVE-2025-50659 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error paramet... |
| CVE-2025-50657 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now