2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60947 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl... |
| CVE-2025-60946 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc... |
| CVE-2025-15606 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz... |
| CVE-2025-15605 | HIGH | 7.3 | 0.1% | Mar 23, 2026 | A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables... |
| CVE-2025-15519 | HIGH | 7.2 | 0.6% | Mar 23, 2026 | Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600... |
| CVE-2025-15518 | HIGH | 7.2 | 0.6% | Mar 23, 2026 | Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600... |
| CVE-2025-15517 | HIGH | 8.1 | 3.1% | Mar 23, 2026 | A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin... |
| CVE-2025-10679 | HIGH | 7.3 | 0.4% | Mar 23, 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for... |
| CVE-2025-14037 | HIGH | 8.1 | 0.2% | Mar 21, 2026 | The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi... |
| CVE-2025-63261 | HIGH | 7.8 | 1.0% | Mar 20, 2026 | AWStats 8.0 is vulnerable to Command Injection via the open function |
| CVE-2025-55988 | HIGH | 7.2 | 0.9% | Mar 20, 2026 | An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire... |
| CVE-2025-67260 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln... |
| CVE-2025-46597 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | Bitcoin Core 0.13.0 through 29.x has an integer overflow. |
| CVE-2025-69720 | HIGH | 7.8 | 0.4% | Mar 19, 2026 | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog... |
| CVE-2025-71260 | HIGH | 8.8 | 34.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ... |
| CVE-2025-71259 | HIGH | 7.1 | 12.9% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
| CVE-2025-71258 | HIGH | 7.1 | 17.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
| CVE-2025-68836 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table... |
| CVE-2025-67618 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro... |
| CVE-2025-53222 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-... |
| CVE-2025-50001 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-58112 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v... |
| CVE-2025-55046 | HIGH | 8.1 | 0.1% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s... |
| CVE-2025-55045 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information... |
| CVE-2025-55044 | HIGH | 8.8 | 0.1% | Mar 18, 2026 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now