2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2322 | CRITICAL | 9.8 | 0.6% | Mar 15, 2025 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affec... |
| CVE-2025-1771 | CRITICAL | 9.8 | 0.6% | Mar 15, 2025 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via t... |
| CVE-2025-2320 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by th... |
| CVE-2025-29775 | CRITICAL | 9.3 | 9.4% | Mar 14, 2025 | xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab... |
| CVE-2025-29774 | CRITICAL | 9.3 | 9.0% | Mar 14, 2025 | xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab... |
| CVE-2025-29386 | CRITICAL | 9.8 | 0.8% | Mar 14, 2025 | In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, w... |
| CVE-2025-29385 | CRITICAL | 9.8 | 0.8% | Mar 14, 2025 | In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerabil... |
| CVE-2025-29384 | CRITICAL | 9.8 | 1.7% | Mar 14, 2025 | In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability... |
| CVE-2025-29031 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function. |
| CVE-2025-29030 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function. |
| CVE-2025-29029 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function. |
| CVE-2025-2304 | CRITICAL | 9.4 | 0.6% | Mar 14, 2025 | A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the ... |
| CVE-2025-2000 | CRITICAL | 9.8 | 0.7% | Mar 14, 2025 | A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation... |
| CVE-2025-27595 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculat... |
| CVE-2025-27593 | CRITICAL | 9.3 | 0.4% | Mar 14, 2025 | The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification check... |
| CVE-2025-2232 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti... |
| CVE-2025-26163 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter. |
| CVE-2025-2263 | CRITICAL | 9.8 | 0.9% | Mar 13, 2025 | During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the u... |
| CVE-2025-2080 | CRITICAL | 9.3 | 0.4% | Mar 13, 2025 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed ... |
| CVE-2025-27138 | CRITICAL | 9.8 | 0.5% | Mar 13, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i... |
| CVE-2025-25292 | CRITICAL | 9.8 | 63.8% | Mar 12, 2025 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul... |
| CVE-2025-25291 | CRITICAL | 9.8 | 19.5% | Mar 12, 2025 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul... |
| CVE-2025-27407 | CRITICAL | 9 | 2.9% | Mar 12, 2025 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13... |
| CVE-2025-25568 | CRITICAL | 9.8 | 0.5% | Mar 12, 2025 | SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. ... |
| CVE-2025-25567 | CRITICAL | 9.8 | 0.6% | Mar 12, 2025 | SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now