2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8899 | HIGH | 8.8 | 0.4% | Mar 7, 2026 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in a... |
| CVE-2025-14353 | HIGH | 7.5 | 0.3% | Mar 7, 2026 | The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc... |
| CVE-2025-69654 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a38... |
| CVE-2025-69650 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed ... |
| CVE-2025-69649 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary wi... |
| CVE-2025-70363 | HIGH | 7.5 | 0.2% | Mar 6, 2026 | Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated ... |
| CVE-2025-15602 | HIGH | 8.8 | 0.5% | Mar 6, 2026 | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently... |
| CVE-2025-59541 | HIGH | 8.1 | 0.2% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability all... |
| CVE-2025-11792 | HIGH | 7.3 | 0.1% | Mar 6, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-11791 | HIGH | 7.1 | 0.1% | Mar 6, 2026 | Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a... |
| CVE-2025-70995 | HIGH | 8.8 | 0.6% | Mar 5, 2026 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code executi... |
| CVE-2025-70949 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a t... |
| CVE-2025-70614 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web... |
| CVE-2025-13350 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: D... |
| CVE-2025-70616 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the I... |
| CVE-2025-45691 | HIGH | 7.5 | 0.5% | Mar 5, 2026 | An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.... |
| CVE-2025-69534 | HIGH | 7.5 | 0.6% | Mar 5, 2026 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser... |
| CVE-2025-69411 | HIGH | 7.5 | 1.6% | Mar 5, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger i... |
| CVE-2025-69340 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad... |
| CVE-2025-69339 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69090 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53335 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15558 | HIGH | 8 | 0.5% | Mar 4, 2026 | Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exis... |
| CVE-2025-59785 | HIGH | 7.2 | 0.2% | Mar 4, 2026 | Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password p... |
| CVE-2025-59784 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now