2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11143 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Different... |
| CVE-2025-66319 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerabilit... |
| CVE-2025-69343 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Thea... |
| CVE-2025-68515 | MEDIUM | 5.8 | 0.3% | Mar 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allow... |
| CVE-2025-41257 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting t... |
| CVE-2025-62879 | MEDIUM | 4.9 | 0.3% | Mar 4, 2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both acce... |
| CVE-2025-59787 | MEDIUM | 6.5 | 0.2% | Mar 4, 2026 | 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving ... |
| CVE-2025-12801 | MEDIUM | 6.5 | 0.5% | Mar 4, 2026 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3... |
| CVE-2025-70342 | MEDIUM | 6.6 | 0.2% | Mar 4, 2026 | erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso... |
| CVE-2025-40896 | MEDIUM | 4.8 | 0.1% | Mar 4, 2026 | The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could per... |
| CVE-2025-40895 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on... |
| CVE-2025-40894 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper valida... |
| CVE-2025-14456 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1 |
| CVE-2025-13734 | MEDIUM | 5.4 | 0.1% | Mar 3, 2026 | IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data ... |
| CVE-2025-13490 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.... |
| CVE-2025-15599 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers... |
| CVE-2025-62816 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4... |
| CVE-2025-62815 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ... |
| CVE-2025-59060 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. ... |
| CVE-2025-15598 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend... |
| CVE-2025-47147 | MEDIUM | 5.7 | 0.1% | Mar 3, 2026 | Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow ... |
| CVE-2025-48644 | MEDIUM | 5.5 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea... |
| CVE-2025-48642 | MEDIUM | 5.5 | 0.1% | Mar 2, 2026 | In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul... |
| CVE-2025-48587 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v... |
| CVE-2025-48585 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now