2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14320 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management... |
| CVE-2025-71284 | CRITICAL | 9.8 | 5.7% | Apr 30, 2026 | Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi... |
| CVE-2025-14543 | CRITICAL | 9.1 | 0.2% | Apr 30, 2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ... |
| CVE-2025-13030 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ... |
| CVE-2025-60889 | CRITICAL | 9.8 | 0.5% | Apr 28, 2026 | Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e... |
| CVE-2025-62373 | CRITICAL | 9.8 | 0.7% | Apr 23, 2026 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0... |
| CVE-2025-50229 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. |
| CVE-2025-41029 | CRITICAL | 9.3 | 0.2% | Apr 21, 2026 | SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ... |
| CVE-2025-15638 | CRITICAL | 10 | 0.6% | Apr 21, 2026 | Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before... |
| CVE-2025-15625 | CRITICAL | 9.8 | 0.4% | Apr 17, 2026 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. |
| CVE-2025-41118 | CRITICAL | 9.1 | 0.4% | Apr 15, 2026 | Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten... |
| CVE-2025-15610 | CRITICAL | 9.3 | 0.3% | Apr 15, 2026 | The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi... |
| CVE-2025-14813 | CRITICAL | 9.3 | 0.3% | Apr 15, 2026 | : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a... |
| CVE-2025-70023 | CRITICAL | 9.8 | 0.4% | Apr 14, 2026 | An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. |
| CVE-2025-65135 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin... |
| CVE-2025-65133 | CRITICAL | 9.8 | 0.5% | Apr 14, 2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ... |
| CVE-2025-63939 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al... |
| CVE-2025-61260 | CRITICAL | 9.8 | 7.1% | Apr 14, 2026 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ... |
| CVE-2025-8095 | CRITICAL | 9.1 | 0.2% | Apr 14, 2026 | The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as crypt... |
| CVE-2025-31991 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut... |
| CVE-2025-44560 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. |
| CVE-2025-13926 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request... |
| CVE-2025-15480 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i... |
| CVE-2025-62718 | CRITICAL | 9.9 | 1.2% | Apr 9, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h... |
| CVE-2025-50228 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now