2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59542 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
| CVE-2025-55289 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V... |
| CVE-2025-70948 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ... |
| CVE-2025-55208 | CRITICAL | 9 | 0.3% | Mar 5, 2026 | Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S... |
| CVE-2025-29165 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component |
| CVE-2025-70233 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard. |
| CVE-2025-70232 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter. |
| CVE-2025-70231 | CRITICAL | 9.8 | 0.7% | Mar 5, 2026 | D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verificati... |
| CVE-2025-70230 | CRITICAL | 9.8 | 0.8% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS. |
| CVE-2025-70229 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule. |
| CVE-2025-13476 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientH... |
| CVE-2025-69338 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C... |
| CVE-2025-68555 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a... |
| CVE-2025-68554 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Fil... |
| CVE-2025-68553 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a... |
| CVE-2025-54001 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects... |
| CVE-2025-40931 | CRITICAL | 9.1 | 0.6% | Mar 5, 2026 | Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD... |
| CVE-2025-40926 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session ... |
| CVE-2025-70222 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuth... |
| CVE-2025-66024 | CRITICAL | 9 | 0.4% | Mar 4, 2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.... |
| CVE-2025-70225 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfi... |
| CVE-2025-70221 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin. |
| CVE-2025-46108 | CRITICAL | 9.8 | 0.6% | Mar 4, 2026 | D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. |
| CVE-2025-70219 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. |
| CVE-2025-70226 | CRITICAL | 9.8 | 0.5% | Mar 4, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now