2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64427 | MEDIUM | 6.5 | 0.2% | Mar 2, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio... |
| CVE-2025-47384 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when MAC configures config id greater than supported maximum value. |
| CVE-2025-47371 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |
| CVE-2025-66880 | MEDIUM | 6.1 | 0.3% | Mar 2, 2026 | Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute... |
| CVE-2025-52564 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani... |
| CVE-2025-52563 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52476 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52475 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52470 | MEDIUM | 4.8 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-52468 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi... |
| CVE-2025-50198 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted... |
| CVE-2025-65465 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earli... |
| CVE-2025-50186 | MEDIUM | 4.8 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-58406 | MEDIUM | 4.3 | 0.2% | Mar 2, 2026 | The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such... |
| CVE-2025-58405 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security ... |
| CVE-2025-30062 | MEDIUM | 6.9 | 0.2% | Mar 2, 2026 | In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection. |
| CVE-2025-15597 | MEDIUM | 6.3 | 0.5% | Mar 2, 2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps... |
| CVE-2025-11950 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Adva... |
| CVE-2025-14142 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t... |
| CVE-2025-9909 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows ... |
| CVE-2025-9908 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerabilit... |
| CVE-2025-9907 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerabi... |
| CVE-2025-9572 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi... |
| CVE-2025-13327 | MEDIUM | 6.3 | 0.1% | Feb 27, 2026 | A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or ins... |
| CVE-2025-15509 | MEDIUM | 4.3 | 0.3% | Feb 27, 2026 | The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now