2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70330 | LOW | 3.3 | 0.2% | Mar 11, 2026 | Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify... |
| CVE-2025-20073 | LOW | 1.8 | 0.1% | Mar 10, 2026 | Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor... |
| CVE-2025-27769 | LOW | 2.6 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC... |
| CVE-2025-68467 | LOW | 3.4 | 0.1% | Mar 4, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the... |
| CVE-2025-36364 | LOW | 3.3 | 0.1% | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the ... |
| CVE-2025-12150 | LOW | 3.1 | 0.2% | Feb 27, 2026 | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf... |
| CVE-2025-15567 | LOW | 3.3 | 0.1% | Feb 27, 2026 | Insufficient protection mechanisms in the Health Module may lead to partial information disclosure. |
| CVE-2025-67860 | LOW | 3.8 | 0.1% | Feb 25, 2026 | A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c... |
| CVE-2025-52603 | LOW | 3.5 | 0.3% | Feb 20, 2026 | HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow ... |
| CVE-2025-14547 | LOW | 2.3 | 0.3% | Feb 20, 2026 | An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs... |
| CVE-2025-14055 | LOW | 2.4 | 0.2% | Feb 20, 2026 | An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special... |
| CVE-2025-14270 | LOW | 2.7 | 0.3% | Feb 19, 2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, ... |
| CVE-2025-8860 | LOW | 3.3 | 0.1% | Feb 18, 2026 | A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t... |
| CVE-2025-36183 | LOW | 2.7 | 0.2% | Feb 17, 2026 | IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e... |
| CVE-2025-14573 | LOW | 2.7 | 0.2% | Feb 16, 2026 | Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team... |
| CVE-2025-69873 | LOW | 2.9 | 0.5% | Feb 11, 2026 | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the... |
| CVE-2025-14594 | LOW | 3.5 | 0.2% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and ... |
| CVE-2025-48509 | LOW | 1.8 | 0.1% | Feb 10, 2026 | Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m... |
| CVE-2025-0029 | LOW | 1.8 | 0.1% | Feb 10, 2026 | Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively ... |
| CVE-2025-33030 | LOW | 3.3 | 0.1% | Feb 10, 2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e... |
| CVE-2025-32739 | LOW | 2.8 | 0.1% | Feb 10, 2026 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic... |
| CVE-2025-31648 | LOW | 3.9 | 0.1% | Feb 10, 2026 | Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg... |
| CVE-2025-25058 | LOW | 3.3 | 0.1% | Feb 10, 2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es... |
| CVE-2025-7432 | LOW | 1 | 0.1% | Feb 9, 2026 | DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an att... |
| CVE-2025-15320 | LOW | 3.3 | 0.1% | Feb 6, 2026 | Tanium addressed a denial of service vulnerability in Tanium Client. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now