2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15598 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend... |
| CVE-2025-47147 | MEDIUM | 5.7 | 0.1% | Mar 3, 2026 | Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow ... |
| CVE-2025-48644 | MEDIUM | 5.5 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea... |
| CVE-2025-48642 | MEDIUM | 5.5 | 0.1% | Mar 2, 2026 | In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul... |
| CVE-2025-48587 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v... |
| CVE-2025-48585 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v... |
| CVE-2025-64427 | MEDIUM | 6.5 | 0.2% | Mar 2, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio... |
| CVE-2025-47384 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when MAC configures config id greater than supported maximum value. |
| CVE-2025-47371 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |
| CVE-2025-66880 | MEDIUM | 6.1 | 0.3% | Mar 2, 2026 | Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute... |
| CVE-2025-52564 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani... |
| CVE-2025-52563 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52476 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52475 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52470 | MEDIUM | 4.8 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-52468 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi... |
| CVE-2025-50198 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted... |
| CVE-2025-65465 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earli... |
| CVE-2025-50186 | MEDIUM | 4.8 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-58406 | MEDIUM | 4.3 | 0.2% | Mar 2, 2026 | The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such... |
| CVE-2025-58405 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security ... |
| CVE-2025-30062 | MEDIUM | 6.9 | 0.2% | Mar 2, 2026 | In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection. |
| CVE-2025-15597 | MEDIUM | 6.3 | 0.5% | Mar 2, 2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps... |
| CVE-2025-11950 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Adva... |
| CVE-2025-14142 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now