2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55263 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i... |
| CVE-2025-55262 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti... |
| CVE-2025-55275 | HIGH | 8.1 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren... |
| CVE-2025-55271 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h... |
| CVE-2025-55265 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files... |
| CVE-2025-41359 | HIGH | 7.8 | 0.2% | Mar 26, 2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo... |
| CVE-2025-41368 | HIGH | 8.1 | 0.6% | Mar 26, 2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us... |
| CVE-2025-15101 | HIGH | 8.8 | 0.9% | Mar 26, 2026 | An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen... |
| CVE-2025-64647 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-14974 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)... |
| CVE-2025-14915 | HIGH | 7.2 | 0.5% | Mar 25, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affecte... |
| CVE-2025-70952 | HIGH | 7.5 | 0.9% | Mar 25, 2026 | pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling ... |
| CVE-2025-70887 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and th... |
| CVE-2025-67030 | HIGH | 8.8 | 0.7% | Mar 25, 2026 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d... |
| CVE-2025-69358 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor... |
| CVE-2025-69347 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploit... |
| CVE-2025-69096 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zork... |
| CVE-2025-27260 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ... |
| CVE-2025-33254 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success... |
| CVE-2025-33248 | HIGH | 7.8 | 0.2% | Mar 24, 2026 | NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin... |
| CVE-2025-33247 | HIGH | 7.8 | 0.3% | Mar 24, 2026 | NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi... |
| CVE-2025-33238 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. ... |
| CVE-2025-64998 | HIGH | 7.2 | 0.3% | Mar 24, 2026 | Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi... |
| CVE-2025-41660 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab... |
| CVE-2025-60949 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now