2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41356 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
| CVE-2025-41355 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t... |
| CVE-2025-10553 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag... |
| CVE-2025-10551 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat... |
| CVE-2025-66215 | MEDIUM | 6.8 | 0.2% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-66038 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com... |
| CVE-2025-66037 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p... |
| CVE-2025-49010 | MEDIUM | 6.8 | 0.1% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-3716 | MEDIUM | 5.3 | 0.2% | Mar 30, 2026 | User enumeration in ESET Protect (on-prem) via Response Timing. |
| CVE-2025-15445 | MEDIUM | 5.4 | 0.2% | Mar 28, 2026 | The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c... |
| CVE-2025-69988 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi... |
| CVE-2025-61190 | MEDIUM | 6.1 | 0.2% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover ... |
| CVE-2025-59031 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen... |
| CVE-2025-55264 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s... |
| CVE-2025-55277 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us... |
| CVE-2025-55276 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz... |
| CVE-2025-55274 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo... |
| CVE-2025-55273 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca... |
| CVE-2025-55272 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw... |
| CVE-2025-55268 | MEDIUM | 5.3 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se... |
| CVE-2025-55266 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr... |
| CVE-2025-41027 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-41026 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-15488 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al... |
| CVE-2025-15433 | MEDIUM | 6.8 | 0.4% | Mar 26, 2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now