2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69437 | HIGH | 8.7 | 0.3% | Feb 27, 2026 | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ... |
| CVE-2025-10990 | HIGH | 7.5 | 0.5% | Feb 27, 2026 | A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin... |
| CVE-2025-40932 | HIGH | 8.2 | 0.2% | Feb 27, 2026 | Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse... |
| CVE-2025-71057 | HIGH | 8.2 | 0.1% | Feb 26, 2026 | Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s... |
| CVE-2025-14343 | HIGH | 7.6 | 0.2% | Feb 26, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T... |
| CVE-2025-14511 | HIGH | 7.5 | 0.4% | Feb 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1... |
| CVE-2025-50180 | HIGH | 7.5 | 0.4% | Feb 25, 2026 | esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-... |
| CVE-2025-0976 | HIGH | 7.5 | 0.2% | Feb 25, 2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This i... |
| CVE-2025-67752 | HIGH | 8.1 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2025-33181 | HIGH | 8.8 | 0.4% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-33180 | HIGH | 8.8 | 0.8% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-33179 | HIGH | 8.8 | 0.5% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-1789 | HIGH | 7.8 | 0.1% | Feb 24, 2026 | Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this ... |
| CVE-2025-14963 | HIGH | 7.8 | 0.1% | Feb 24, 2026 | A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil... |
| CVE-2025-13776 | HIGH | 7.1 | 0.1% | Feb 24, 2026 | Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A m... |
| CVE-2025-63409 | HIGH | 8.8 | 0.3% | Feb 24, 2026 | Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to mod... |
| CVE-2025-67445 | HIGH | 7.5 | 0.4% | Feb 24, 2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read... |
| CVE-2025-40541 | HIGH | 7.2 | 0.6% | Feb 24, 2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor... |
| CVE-2025-40540 | HIGH | 7.2 | 0.4% | Feb 24, 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb... |
| CVE-2025-40539 | HIGH | 7.2 | 0.4% | Feb 24, 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb... |
| CVE-2025-40538 | HIGH | 7.2 | 0.5% | Feb 24, 2026 | A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea... |
| CVE-2025-15589 | HIGH | 7.2 | 0.7% | Feb 24, 2026 | A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/co... |
| CVE-2025-15386 | HIGH | 8.8 | 0.3% | Feb 24, 2026 | The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack du... |
| CVE-2025-13943 | HIGH | 8.8 | 1.4% | Feb 24, 2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ... |
| CVE-2025-9120 | HIGH | 8.6 | 0.2% | Feb 24, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now