2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66956 | CRITICAL | 9.9 | 0.6% | Mar 11, 2026 | Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t... |
| CVE-2025-67039 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe... |
| CVE-2025-67038 | CRITICAL | 9.8 | 22.0% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ... |
| CVE-2025-69615 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n... |
| CVE-2025-69614 | CRITICAL | 9.4 | 0.4% | Mar 10, 2026 | Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets... |
| CVE-2025-56422 | CRITICAL | 9.8 | 0.9% | Mar 10, 2026 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o... |
| CVE-2025-41709 | CRITICAL | 9.8 | 2.2% | Mar 10, 2026 | An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a... |
| CVE-2025-40943 | CRITICAL | 9.6 | 0.5% | Mar 10, 2026 | Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug... |
| CVE-2025-11158 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric... |
| CVE-2025-70039 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag... |
| CVE-2025-70046 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro... |
| CVE-2025-70042 | CRITICAL | 9.8 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. |
| CVE-2025-40639 | CRITICAL | 9.8 | 0.3% | Mar 9, 2026 | A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up... |
| CVE-2025-41765 | CRITICAL | 9.1 | 0.3% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to... |
| CVE-2025-41764 | CRITICAL | 9.1 | 0.4% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to... |
| CVE-2025-59543 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
| CVE-2025-59542 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
| CVE-2025-55289 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V... |
| CVE-2025-70948 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ... |
| CVE-2025-55208 | CRITICAL | 9 | 0.3% | Mar 5, 2026 | Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S... |
| CVE-2025-29165 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component |
| CVE-2025-70233 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard. |
| CVE-2025-70232 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter. |
| CVE-2025-70231 | CRITICAL | 9.8 | 0.7% | Mar 5, 2026 | D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verificati... |
| CVE-2025-70230 | CRITICAL | 9.8 | 0.8% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now