2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25565 | CRITICAL | 9.8 | 0.6% | Mar 12, 2025 | SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 fun... |
| CVE-2025-1960 | CRITICAL | 9.8 | 0.5% | Mar 12, 2025 | CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to exe... |
| CVE-2025-22954 | CRITICAL | 10 | 23.2% | Mar 12, 2025 | GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi... |
| CVE-2025-2219 | CRITICAL | 9.8 | 0.6% | Mar 12, 2025 | A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unkno... |
| CVE-2025-2218 | CRITICAL | 9.8 | 0.7% | Mar 12, 2025 | A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affec... |
| CVE-2025-2217 | CRITICAL | 9.8 | 0.7% | Mar 12, 2025 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This ... |
| CVE-2025-2216 | CRITICAL | 9.8 | 0.7% | Mar 12, 2025 | A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. ... |
| CVE-2025-28915 | CRITICAL | 9.1 | 1.2% | Mar 11, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Uplo... |
| CVE-2025-28872 | CRITICAL | 9.8 | 0.5% | Mar 11, 2025 | Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing... |
| CVE-2025-23360 | CRITICAL | 9.8 | 0.5% | Mar 11, 2025 | NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil... |
| CVE-2025-23243 | CRITICAL | 9.1 | 2.0% | Mar 11, 2025 | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ... |
| CVE-2025-23242 | CRITICAL | 9.8 | 1.9% | Mar 11, 2025 | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ... |
| CVE-2025-26701 | CRITICAL | 10 | 0.4% | Mar 11, 2025 | An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead... |
| CVE-2025-24201 | CRITICAL | 10 | 4.2% | Mar 11, 2025 | An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in ... |
| CVE-2025-1550 | CRITICAL | 9.8 | 2.8% | Mar 11, 2025 | The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually const... |
| CVE-2025-1661 | CRITICAL | 9.8 | 52.8% | Mar 11, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2025-27925 | CRITICAL | 9.8 | 0.4% | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. |
| CVE-2025-25306 | CRITICAL | 9.3 | 0.2% | Mar 10, 2025 | Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate t... |
| CVE-2025-24813 | CRITICAL | 9.8 | 99.9% | Mar 10, 2025 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malic... |
| CVE-2025-25977 | CRITICAL | 9.8 | 0.6% | Mar 10, 2025 | An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement. |
| CVE-2025-25940 | CRITICAL | 9.8 | 0.7% | Mar 10, 2025 | VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java. |
| CVE-2025-26936 | CRITICAL | 10 | 0.5% | Mar 10, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework all... |
| CVE-2025-26916 | CRITICAL | 9 | 0.6% | Mar 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-2152 | CRITICAL | 9.8 | 0.5% | Mar 10, 2025 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ... |
| CVE-2025-1497 | CRITICAL | 9.8 | 1.0% | Mar 10, 2025 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-g... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now