2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13723 | HIGH | 7.5 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o... |
| CVE-2025-13718 | HIGH | 7.5 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke... |
| CVE-2025-12455 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability co... |
| CVE-2025-70873 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier al... |
| CVE-2025-68623 | HIGH | 8.8 | 0.1% | Mar 11, 2026 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file dur... |
| CVE-2025-67037 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunne... |
| CVE-2025-67036 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying th... |
| CVE-2025-67034 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name"... |
| CVE-2025-14513 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ... |
| CVE-2025-13929 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-12690 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF... |
| CVE-2025-70027 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This ... |
| CVE-2025-67298 | HIGH | 8.1 | 0.2% | Mar 11, 2026 | An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and ... |
| CVE-2025-13067 | HIGH | 8.8 | 0.5% | Mar 11, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in... |
| CVE-2025-20105 | HIGH | 8.7 | 0.1% | Mar 10, 2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ... |
| CVE-2025-20068 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati... |
| CVE-2025-20064 | HIGH | 8.7 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation... |
| CVE-2025-20028 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e... |
| CVE-2025-20027 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p... |
| CVE-2025-70802 | HIGH | 8.4 | 0.2% | Mar 10, 2026 | Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh... |
| CVE-2025-70798 | HIGH | 8.4 | 0.2% | Mar 10, 2026 | Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado... |
| CVE-2025-70244 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup. |
| CVE-2025-36920 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validatio... |
| CVE-2025-70251 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup. |
| CVE-2025-70249 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now