2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62846 | MEDIUM | 6.7 | 0.2% | Mar 20, 2026 | An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th... |
| CVE-2025-62845 | MEDIUM | 6.7 | 0.2% | Mar 20, 2026 | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l... |
| CVE-2025-62844 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c... |
| CVE-2025-62843 | MEDIUM | 6.8 | 0.3% | Mar 20, 2026 | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. ... |
| CVE-2025-46598 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. |
| CVE-2025-67115 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor... |
| CVE-2025-14716 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue... |
| CVE-2025-62043 | MEDIUM | 6.5 | 0.1% | Mar 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all... |
| CVE-2025-32223 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ... |
| CVE-2025-36051 | MEDIUM | 5.5 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th... |
| CVE-2025-15051 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2025-13995 | MEDIUM | 5 | 0.2% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna... |
| CVE-2025-71270 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ... |
| CVE-2025-71269 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro... |
| CVE-2025-71268 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe... |
| CVE-2025-55043 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m... |
| CVE-2025-71267 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size... |
| CVE-2025-71266 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid... |
| CVE-2025-71265 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang... |
| CVE-2025-12518 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious ... |
| CVE-2025-15363 | MEDIUM | 5.9 | 0.1% | Mar 18, 2026 | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c... |
| CVE-2025-14806 | MEDIUM | 5.7 | 0.3% | Mar 17, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an... |
| CVE-2025-15584 | MEDIUM | 6.8 | 0.1% | Mar 17, 2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2025-13406 | MEDIUM | 6.8 | 0.3% | Mar 17, 2026 | NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ... |
| CVE-2025-62320 | MEDIUM | 6.1 | 0.2% | Mar 17, 2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now