2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43857 | MEDIUM | 6.5 | 0.4% | Apr 28, 2025 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.... |
| CVE-2025-43854 | MEDIUM | 6.1 | 0.2% | Apr 28, 2025 | DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in t... |
| CVE-2025-25776 | MEDIUM | 5 | 0.2% | Apr 28, 2025 | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Tick... |
| CVE-2025-23376 | MEDIUM | 4.4 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Speci... |
| CVE-2025-32472 | MEDIUM | 5.3 | 0.5% | Apr 28, 2025 | The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulner... |
| CVE-2025-4017 | MEDIUM | 6.5 | 0.4% | Apr 28, 2025 | A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f16... |
| CVE-2025-4011 | MEDIUM | 5.1 | 0.3% | Apr 28, 2025 | A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affe... |
| CVE-2025-39367 | MEDIUM | 5.3 | 0.2% | Apr 28, 2025 | Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4. |
| CVE-2025-4006 | MEDIUM | 5.1 | 0.3% | Apr 28, 2025 | A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the... |
| CVE-2025-4003 | MEDIUM | 6.8 | 0.2% | Apr 28, 2025 | A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects th... |
| CVE-2025-4002 | MEDIUM | 6.8 | 0.2% | Apr 28, 2025 | A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue i... |
| CVE-2025-4001 | MEDIUM | 4.8 | 0.2% | Apr 28, 2025 | A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability... |
| CVE-2025-4000 | MEDIUM | 5.4 | 0.3% | Apr 28, 2025 | A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Aff... |
| CVE-2025-3999 | MEDIUM | 5.4 | 0.3% | Apr 28, 2025 | A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2... |
| CVE-2025-3997 | MEDIUM | 5.3 | 0.2% | Apr 28, 2025 | A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the fi... |
| CVE-2025-3996 | MEDIUM | 4.8 | 0.3% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue i... |
| CVE-2025-3706 | MEDIUM | 6.1 | 0.3% | Apr 28, 2025 | The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-31144 | MEDIUM | 6.9 | 0.4% | Apr 28, 2025 | Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoi... |
| CVE-2025-46689 | MEDIUM | 6.1 | 0.2% | Apr 27, 2025 | Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI. |
| CVE-2025-3985 | MEDIUM | 4.9 | 0.5% | Apr 27, 2025 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function Response... |
| CVE-2025-3981 | MEDIUM | 5.3 | 0.3% | Apr 27, 2025 | A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstatio... |
| CVE-2025-2866 | MEDIUM | 5.5 | 0.1% | Apr 27, 2025 | Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper ... |
| CVE-2025-3980 | MEDIUM | 5.3 | 3.7% | Apr 27, 2025 | A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. Thi... |
| CVE-2025-3979 | MEDIUM | 6.5 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the fi... |
| CVE-2025-3977 | MEDIUM | 5.3 | 0.3% | Apr 27, 2025 | A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now