2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62675 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
| CVE-2025-43892 | MEDIUM | 4.3 | — | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v... |
| CVE-2025-15665 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl... |
| CVE-2025-5017 | MEDIUM | 4.9 | 0.3% | Jul 11, 2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’... |
| CVE-2025-13968 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod... |
| CVE-2025-30008 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users... |
| CVE-2025-11977 | MEDIUM | 6.6 | 0.5% | Jul 10, 2026 | The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo... |
| CVE-2025-12506 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ... |
| CVE-2025-14785 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor... |
| CVE-2025-12799 | MEDIUM | 6.5 | 0.2% | Jul 7, 2026 | A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config... |
| CVE-2025-8591 | MEDIUM | 6.1 | 0.2% | Jul 6, 2026 | The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back ... |
| CVE-2025-71385 | MEDIUM | 6.1 | 0.2% | Jul 2, 2026 | Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi... |
| CVE-2025-69132 | MEDIUM | 6.5 | — | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. |
| CVE-2025-66076 | MEDIUM | 5.3 | — | Jul 2, 2026 | Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions. |
| CVE-2025-15666 | MEDIUM | 5.3 | 0.1% | Jul 1, 2026 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili... |
| CVE-2025-71381 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd... |
| CVE-2025-36359 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow... |
| CVE-2025-36336 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob... |
| CVE-2025-36333 | MEDIUM | 4.3 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio... |
| CVE-2025-36328 | MEDIUM | 4.3 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w... |
| CVE-2025-36327 | MEDIUM | 6.5 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls a... |
| CVE-2025-36324 | MEDIUM | 4.3 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may al... |
| CVE-2025-36323 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2025-36321 | MEDIUM | 5.7 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject... |
| CVE-2025-36320 | MEDIUM | 6.4 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerabilit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now