2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3522 | MEDIUM | 6.3 | 0.2% | Apr 15, 2025 | Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally.... |
| CVE-2025-32949 | MEDIUM | 6.5 | 0.5% | Apr 15, 2025 | This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex... |
| CVE-2025-2830 | MEDIUM | 6.3 | 0.3% | Apr 15, 2025 | By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu... |
| CVE-2025-28145 | MEDIUM | 6.5 | 8.0% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-28144 | MEDIUM | 6.5 | 3.8% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili... |
| CVE-2025-28143 | MEDIUM | 6.5 | 7.7% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-28142 | MEDIUM | 6.5 | 8.0% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-27980 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=. |
| CVE-2025-29280 | MEDIUM | 4.8 | 0.2% | Apr 15, 2025 | Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system ... |
| CVE-2025-28136 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi. |
| CVE-2025-3608 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea... |
| CVE-2025-32946 | MEDIUM | 5.3 | 0.3% | Apr 15, 2025 | This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. Th... |
| CVE-2025-32945 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. Th... |
| CVE-2025-32944 | MEDIUM | 6.5 | 0.5% | Apr 15, 2025 | The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.... |
| CVE-2025-32103 | MEDIUM | 5 | 12.2% | Apr 15, 2025 | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ ... |
| CVE-2025-32102 | MEDIUM | 5 | 5.7% | Apr 15, 2025 | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=t... |
| CVE-2025-30965 | MEDIUM | 4.3 | 0.1% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue aff... |
| CVE-2025-30964 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forger... |
| CVE-2025-26990 | MEDIUM | 4.9 | 0.2% | Apr 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server... |
| CVE-2025-26982 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächle... |
| CVE-2025-26955 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured... |
| CVE-2025-26745 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Element... |
| CVE-2025-26744 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-32943 | MEDIUM | 4.3 | 0.4% | Apr 15, 2025 | The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server... |
| CVE-2025-1688 | MEDIUM | 5.5 | 0.2% | Apr 15, 2025 | Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configurati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now