2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37893 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prolo... |
| CVE-2025-37860 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_... |
| CVE-2025-3598 | MEDIUM | 6.1 | 0.4% | Apr 18, 2025 | The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2025-2162 | MEDIUM | 4.8 | 0.3% | Apr 18, 2025 | The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-2613 | MEDIUM | 4.4 | 0.2% | Apr 18, 2025 | The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S... |
| CVE-2025-25427 | MEDIUM | 5.4 | 0.6% | Apr 18, 2025 | A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/... |
| CVE-2025-3124 | MEDIUM | 4.3 | 0.4% | Apr 17, 2025 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of... |
| CVE-2025-29456 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29453 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29455 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29454 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in... |
| CVE-2025-29450 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp... |
| CVE-2025-29449 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio... |
| CVE-2025-29316 | MEDIUM | 6.2 | 0.2% | Apr 17, 2025 | An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t... |
| CVE-2025-29722 | MEDIUM | 6.3 | 0.2% | Apr 17, 2025 | A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat... |
| CVE-2025-28101 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele... |
| CVE-2025-26269 | MEDIUM | 5.5 | 0.2% | Apr 17, 2025 | DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon c... |
| CVE-2025-26268 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted... |
| CVE-2025-43015 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces |
| CVE-2025-43014 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation |
| CVE-2025-42921 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin |
| CVE-2025-39580 | MEDIUM | 5.8 | 0.2% | Apr 17, 2025 | Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ... |
| CVE-2025-39562 | MEDIUM | 5.9 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment... |
| CVE-2025-39559 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce bring-fraktguiden-for-woocommerce a... |
| CVE-2025-39554 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | Missing Authorization vulnerability in Elliot Sowersby / RelyWP AI Text to Speech ai-text-to-speech allows Exploiting In... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now