2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31935 | MEDIUM | 6.9 | 0.2% | Apr 11, 2025 | Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data... |
| CVE-2025-31354 | MEDIUM | 5.3 | 0.1% | Apr 11, 2025 | Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with cra... |
| CVE-2025-32427 | MEDIUM | 5.4 | 0.2% | Apr 11, 2025 | Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or... |
| CVE-2025-32426 | MEDIUM | 5.4 | 0.2% | Apr 11, 2025 | Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into t... |
| CVE-2025-3422 | MEDIUM | 6.3 | 0.3% | Apr 11, 2025 | The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress... |
| CVE-2025-3421 | MEDIUM | 6.1 | 0.3% | Apr 11, 2025 | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ... |
| CVE-2025-2575 | MEDIUM | 5.4 | 0.3% | Apr 11, 2025 | The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u... |
| CVE-2025-2541 | MEDIUM | 5.4 | 0.3% | Apr 11, 2025 | The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2025-23387 | MEDIUM | 5.3 | 0.5% | Apr 11, 2025 | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users... |
| CVE-2025-2128 | MEDIUM | 6.5 | 0.3% | Apr 11, 2025 | The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter... |
| CVE-2025-32598 | MEDIUM | 6.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Table Builder W... |
| CVE-2025-3512 | MEDIUM | 4.8 | 0.2% | Apr 11, 2025 | There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted mar... |
| CVE-2025-1386 | MEDIUM | 4.9 | 0.3% | Apr 11, 2025 | When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious externa... |
| CVE-2025-26335 | MEDIUM | 4.9 | 0.3% | Apr 11, 2025 | Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent ... |
| CVE-2025-0125 | MEDIUM | 6.9 | 0.3% | Apr 11, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
| CVE-2025-0122 | MEDIUM | 5.1 | 0.2% | Apr 11, 2025 | A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated atta... |
| CVE-2025-0121 | MEDIUM | 6.8 | 0.1% | Apr 11, 2025 | A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-pri... |
| CVE-2025-32809 | MEDIUM | 5.4 | 0.2% | Apr 11, 2025 | W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus ... |
| CVE-2025-32807 | MEDIUM | 5.3 | 0.5% | Apr 11, 2025 | A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host... |
| CVE-2025-29918 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ... |
| CVE-2025-29917 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th... |
| CVE-2025-29916 | MEDIUM | 5.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Da... |
| CVE-2025-22232 | MEDIUM | 5.3 | 0.3% | Apr 10, 2025 | Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to... |
| CVE-2025-32027 | MEDIUM | 6.1 | 0.2% | Apr 10, 2025 | Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenari... |
| CVE-2025-29150 | MEDIUM | 4.3 | 0.3% | Apr 10, 2025 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now