2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2770 | MEDIUM | 6.5 | 0.4% | Apr 23, 2025 | BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al... |
| CVE-2025-2763 | MEDIUM | 6.8 | 0.2% | Apr 23, 2025 | CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-29526 | MEDIUM | 6.1 | 0.2% | Apr 23, 2025 | A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allow... |
| CVE-2025-28017 | MEDIUM | 6.5 | 1.1% | Apr 23, 2025 | TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING param... |
| CVE-2025-1522 | MEDIUM | 6.5 | 0.5% | Apr 23, 2025 | PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remo... |
| CVE-2025-1521 | MEDIUM | 6.5 | 0.5% | Apr 23, 2025 | PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allo... |
| CVE-2025-46393 | MEDIUM | 5.3 | 0.3% | Apr 23, 2025 | In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the renderi... |
| CVE-2025-43716 | MEDIUM | 5.8 | 1.2% | Apr 23, 2025 | A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to... |
| CVE-2025-2703 | MEDIUM | 6.8 | 10.6% | Apr 23, 2025 | The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif... |
| CVE-2025-42604 | MEDIUM | 6.9 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker... |
| CVE-2025-1054 | MEDIUM | 6.4 | 0.2% | Apr 23, 2025 | The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2025-2595 | MEDIUM | 5.3 | 0.4% | Apr 23, 2025 | An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa... |
| CVE-2025-0618 | MEDIUM | 6.5 | 0.6% | Apr 23, 2025 | A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec... |
| CVE-2025-1056 | MEDIUM | 6.5 | 0.2% | Apr 23, 2025 | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the ... |
| CVE-2025-37088 | MEDIUM | 6.8 | 0.1% | Apr 22, 2025 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions... |
| CVE-2025-27087 | MEDIUM | 5.5 | 0.2% | Apr 22, 2025 | A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se... |
| CVE-2025-29743 | MEDIUM | 6.5 | 1.0% | Apr 22, 2025 | D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting. |
| CVE-2025-26159 | MEDIUM | 6.1 | 0.3% | Apr 22, 2025 | Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of cr... |
| CVE-2025-31328 | MEDIUM | 4.6 | 0.1% | Apr 22, 2025 | SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated us... |
| CVE-2025-31327 | MEDIUM | 4.3 | 0.2% | Apr 22, 2025 | SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which ... |
| CVE-2025-43952 | MEDIUM | 6.1 | 0.2% | Apr 22, 2025 | A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0... |
| CVE-2025-32964 | MEDIUM | 4.6 | 0.2% | Apr 22, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting... |
| CVE-2025-32963 | MEDIUM | 6.9 | 0.5% | Apr 22, 2025 | MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided f... |
| CVE-2025-32961 | MEDIUM | 6.4 | 0.3% | Apr 22, 2025 | The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTT... |
| CVE-2025-32960 | MEDIUM | 6.4 | 0.3% | Apr 22, 2025 | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now