2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71405 | MEDIUM | 5.1 | — | Aug 14, 2026 | chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses t... |
| CVE-2025-10308 | MEDIUM | 4.3 | — | Aug 14, 2026 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-62318 | LOW | 3.7 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages... |
| CVE-2025-62315 | LOW | 3.4 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validatio... |
| CVE-2025-62314 | MEDIUM | 5.6 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s... |
| CVE-2025-52640 | MEDIUM | 4.7 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi... |
| CVE-2025-9486 | LOW | 3.3 | — | Aug 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2... |
| CVE-2025-35988 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-35977 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-32737 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-32087 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-32084 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-31943 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-30178 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-27570 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-27245 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-25275 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-24837 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-24488 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-20020 | — | — | — | Aug 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused |
| CVE-2025-59324 | CRITICAL | 9.1 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is ... |
| CVE-2025-59323 | HIGH | 8.4 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition... |
| CVE-2025-59322 | HIGH | 7.5 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v... |
| CVE-2025-59321 | CRITICAL | 9.8 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst... |
| CVE-2025-59320 | MEDIUM | 4.6 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now