2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4088 | MEDIUM | 6.5 | 0.1% | Apr 29, 2025 | A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitr... |
| CVE-2025-4087 | MEDIUM | 4.8 | 0.3% | Apr 29, 2025 | A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null c... |
| CVE-2025-4086 | MEDIUM | 6.5 | 0.2% | Apr 29, 2025 | A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension ... |
| CVE-2025-4084 | MEDIUM | 5.7 | 0.3% | Apr 29, 2025 | Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user int... |
| CVE-2025-4082 | MEDIUM | 5.9 | 0.4% | Apr 29, 2025 | Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vul... |
| CVE-2025-4064 | MEDIUM | 6.9 | 0.4% | Apr 29, 2025 | A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects... |
| CVE-2025-4035 | MEDIUM | 4.3 | 0.3% | Apr 29, 2025 | A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix... |
| CVE-2025-3929 | MEDIUM | 6.1 | 0.5% | Apr 29, 2025 | An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted H... |
| CVE-2025-1194 | MEDIUM | 6.5 | 0.4% | Apr 29, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe... |
| CVE-2025-3452 | MEDIUM | 4.3 | 0.2% | Apr 29, 2025 | The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-2893 | MEDIUM | 5.4 | 0.2% | Apr 29, 2025 | The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-46343 | MEDIUM | 5.4 | 0.2% | Apr 29, 2025 | n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t... |
| CVE-2025-46338 | MEDIUM | 6.1 | 0.3% | Apr 29, 2025 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulner... |
| CVE-2025-31203 | MEDIUM | 6.5 | 0.3% | Apr 29, 2025 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO... |
| CVE-2025-31202 | MEDIUM | 5.5 | 0.2% | Apr 29, 2025 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4... |
| CVE-2025-31197 | MEDIUM | 5.7 | 0.2% | Apr 29, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ... |
| CVE-2025-30445 | MEDIUM | 6.5 | 0.3% | Apr 29, 2025 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.... |
| CVE-2025-24271 | MEDIUM | 5.4 | 0.4% | Apr 29, 2025 | An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS... |
| CVE-2025-24270 | MEDIUM | 5.7 | 0.3% | Apr 29, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6... |
| CVE-2025-24251 | MEDIUM | 6.5 | 0.3% | Apr 29, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ... |
| CVE-2025-24179 | MEDIUM | 5.7 | 0.2% | Apr 29, 2025 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3... |
| CVE-2025-4038 | MEDIUM | 5.5 | 0.3% | Apr 28, 2025 | A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affect... |
| CVE-2025-4037 | MEDIUM | 5.5 | 0.2% | Apr 28, 2025 | A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function... |
| CVE-2025-0049 | MEDIUM | 4.3 | 0.2% | Apr 28, 2025 | When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error... |
| CVE-2025-34490 | MEDIUM | 6.5 | 0.6% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now