2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12518 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious ... |
| CVE-2025-15363 | MEDIUM | 5.9 | 0.1% | Mar 18, 2026 | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c... |
| CVE-2025-14806 | MEDIUM | 5.7 | 0.3% | Mar 17, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an... |
| CVE-2025-15584 | MEDIUM | 6.8 | 0.1% | Mar 17, 2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2025-13406 | MEDIUM | 6.8 | 0.3% | Mar 17, 2026 | NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ... |
| CVE-2025-62320 | MEDIUM | 6.1 | 0.2% | Mar 17, 2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s... |
| CVE-2025-71239 | MEDIUM | 5.5 | 0.1% | Mar 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class ... |
| CVE-2025-69693 | MEDIUM | 5.4 | 0.3% | Mar 16, 2026 | Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) va... |
| CVE-2025-68971 | MEDIUM | 6.5 | 0.5% | Mar 16, 2026 | In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach... |
| CVE-2025-69727 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (... |
| CVE-2025-69196 | MEDIUM | 6.5 | 0.4% | Mar 16, 2026 | FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r... |
| CVE-2025-65734 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, ... |
| CVE-2025-57543 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra... |
| CVE-2025-52649 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ... |
| CVE-2025-52646 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52645 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut... |
| CVE-2025-52642 | MEDIUM | 6.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ... |
| CVE-2025-2274 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store... |
| CVE-2025-71264 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash). |
| CVE-2025-6969 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-69245 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici... |
| CVE-2025-69243 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta... |
| CVE-2025-69242 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ... |
| CVE-2025-69241 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic... |
| CVE-2025-69238 | MEDIUM | 4.3 | 0.1% | Mar 16, 2026 | Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now