2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70234 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS. |
| CVE-2025-70241 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5. |
| CVE-2025-70237 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr. |
| CVE-2025-70236 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter. |
| CVE-2025-66945 | CRITICAL | 9.1 | 0.5% | Mar 3, 2026 | A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed... |
| CVE-2025-14923 | CRITICAL | 9.8 | 0.2% | Mar 3, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-70821 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component |
| CVE-2025-57622 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ... |
| CVE-2025-59059 | CRITICAL | 9.8 | 1.2% | Mar 3, 2026 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ... |
| CVE-2025-48609 | CRITICAL | 9.1 | 0.3% | Mar 2, 2026 | In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S... |
| CVE-2025-52998 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor... |
| CVE-2025-50199 | CRITICAL | 9.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via... |
| CVE-2025-50192 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main... |
| CVE-2025-50190 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope... |
| CVE-2025-50187 | CRITICAL | 9.8 | 0.9% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt... |
| CVE-2025-14532 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension... |
| CVE-2025-12462 | CRITICAL | 9.3 | 0.4% | Mar 2, 2026 | A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to injec... |
| CVE-2025-30044 | CRITICAL | 9.4 | 0.5% | Mar 2, 2026 | In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-... |
| CVE-2025-30035 | CRITICAL | 9 | 0.2% | Mar 2, 2026 | The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ... |
| CVE-2025-15498 | CRITICAL | 9.3 | 0.5% | Feb 27, 2026 | Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ... |
| CVE-2025-11252 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ... |
| CVE-2025-11251 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I... |
| CVE-2025-12981 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i... |
| CVE-2025-50857 | CRITICAL | 9.8 | 2.3% | Feb 26, 2026 | ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker... |
| CVE-2025-69771 | CRITICAL | 9.6 | 0.3% | Feb 25, 2026 | Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now