2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2070 | MEDIUM | 5.1 | 0.1% | Apr 25, 2025 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the syst... |
| CVE-2025-2069 | MEDIUM | 5.1 | 0.2% | Apr 25, 2025 | A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted ur... |
| CVE-2025-2068 | MEDIUM | 5.1 | 0.1% | Apr 25, 2025 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url... |
| CVE-2025-46618 | MEDIUM | 6.1 | 22.0% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab |
| CVE-2025-46432 | MEDIUM | 6.5 | 0.8% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs |
| CVE-2025-3647 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they a... |
| CVE-2025-3645 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users'... |
| CVE-2025-3644 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not ... |
| CVE-2025-3643 | MEDIUM | 5.4 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cros... |
| CVE-2025-3640 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access so... |
| CVE-2025-3636 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficien... |
| CVE-2025-3628 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student... |
| CVE-2025-3627 | MEDIUM | 4.3 | 0.3% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other stu... |
| CVE-2025-32045 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without... |
| CVE-2025-28076 | MEDIUM | 6.5 | 0.3% | Apr 25, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated at... |
| CVE-2025-3634 | MEDIUM | 4.3 | 0.2% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completin... |
| CVE-2025-28354 | MEDIUM | 6.5 | 0.5% | Apr 25, 2025 | An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a ... |
| CVE-2025-3912 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-2986 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged... |
| CVE-2025-3870 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-46535 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly C... |
| CVE-2025-46482 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Qui... |
| CVE-2025-3868 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'... |
| CVE-2025-3867 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-3866 | MEDIUM | 6.1 | 0.3% | Apr 25, 2025 | The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now