2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24887 | MEDIUM | 6.3 | 0.2% | Apr 30, 2025 | OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allo... |
| CVE-2025-4135 | MEDIUM | 6.3 | 2.3% | Apr 30, 2025 | A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the funct... |
| CVE-2025-24091 | MEDIUM | 5.5 | 0.3% | Apr 30, 2025 | An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue i... |
| CVE-2025-3859 | MEDIUM | 6.1 | 0.2% | Apr 30, 2025 | Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be... |
| CVE-2025-32972 | MEDIUM | 5.3 | 0.4% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to befo... |
| CVE-2025-32970 | MEDIUM | 6.1 | 0.5% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.... |
| CVE-2025-32376 | MEDIUM | 4.3 | 0.2% | Apr 30, 2025 | Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the bet... |
| CVE-2025-45021 | MEDIUM | 5.3 | 0.2% | Apr 30, 2025 | A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management... |
| CVE-2025-45019 | MEDIUM | 5.4 | 0.4% | Apr 30, 2025 | A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management ... |
| CVE-2025-45015 | MEDIUM | 6.1 | 0.3% | Apr 30, 2025 | A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGuruku... |
| CVE-2025-45011 | MEDIUM | 5.3 | 0.3% | Apr 30, 2025 | A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management S... |
| CVE-2025-45010 | MEDIUM | 5.3 | 0.3% | Apr 30, 2025 | A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketin... |
| CVE-2025-45009 | MEDIUM | 5.3 | 0.3% | Apr 30, 2025 | A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management Syst... |
| CVE-2025-45007 | MEDIUM | 4.8 | 0.3% | Apr 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Gene... |
| CVE-2025-3395 | MEDIUM | 5.5 | 0.1% | Apr 30, 2025 | Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A... |
| CVE-2025-27532 | MEDIUM | 6.5 | 2.6% | Apr 30, 2025 | A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows a remote authenticated... |
| CVE-2025-24348 | MEDIUM | 5.4 | 0.4% | Apr 30, 2025 | A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat... |
| CVE-2025-24347 | MEDIUM | 6.5 | 0.4% | Apr 30, 2025 | A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat... |
| CVE-2025-24345 | MEDIUM | 6.3 | 0.3% | Apr 30, 2025 | A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privi... |
| CVE-2025-24344 | MEDIUM | 6.3 | 0.3% | Apr 30, 2025 | A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated at... |
| CVE-2025-24343 | MEDIUM | 5.4 | 0.4% | Apr 30, 2025 | A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated... |
| CVE-2025-24342 | MEDIUM | 5.3 | 0.4% | Apr 30, 2025 | A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker t... |
| CVE-2025-24341 | MEDIUM | 6.5 | 0.4% | Apr 30, 2025 | A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a D... |
| CVE-2025-24340 | MEDIUM | 6.5 | 0.2% | Apr 30, 2025 | A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker t... |
| CVE-2025-24339 | MEDIUM | 5 | 0.2% | Apr 30, 2025 | A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now