2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2528 | LOW | 3.6 | 0.2% | Mar 26, 2025 | Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authent... |
| CVE-2025-24808 | LOW | 3.1 | 0.2% | Mar 26, 2025 | Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t... |
| CVE-2025-30222 | LOW | 2.1 | 0.2% | Mar 25, 2025 | Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential envir... |
| CVE-2025-1452 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2025-0717 | LOW | 3.5 | 0.2% | Mar 25, 2025 | To exploit the vulnerability, it is necessary: |
| CVE-2025-1203 | LOW | 3.5 | 0.3% | Mar 24, 2025 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its... |
| CVE-2025-1062 | LOW | 3.5 | 0.2% | Mar 24, 2025 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its... |
| CVE-2025-2588 | LOW | 3.3 | 0.2% | Mar 21, 2025 | A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the f... |
| CVE-2025-27715 | LOW | 2.7 | 0.2% | Mar 21, 2025 | Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channe... |
| CVE-2025-30344 | LOW | 3.7 | 0.3% | Mar 21, 2025 | An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's respo... |
| CVE-2025-2574 | LOW | 2.1 | 0.2% | Mar 20, 2025 | Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript functio... |
| CVE-2025-2555 | LOW | 2.9 | 0.2% | Mar 20, 2025 | A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unkn... |
| CVE-2025-29923 | LOW | 3.7 | 0.7% | Mar 20, 2025 | go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redi... |
| CVE-2025-30259 | LOW | 3.5 | 0.2% | Mar 20, 2025 | The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protecti... |
| CVE-2025-30197 | LOW | 3.1 | 0.3% | Mar 19, 2025 | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing t... |
| CVE-2025-30235 | LOW | 3.5 | 0.2% | Mar 19, 2025 | Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed... |
| CVE-2025-25040 | LOW | 3.3 | 0.1% | Mar 18, 2025 | A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking... |
| CVE-2025-29431 | LOW | 3.2 | 0.2% | Mar 17, 2025 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/departm... |
| CVE-2025-27512 | LOW | 2.1 | 0.2% | Mar 17, 2025 | Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system u... |
| CVE-2025-25618 | LOW | 3.3 | 0.4% | Mar 17, 2025 | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and R... |
| CVE-2025-1398 | LOW | 3.3 | 0.2% | Mar 17, 2025 | Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker wit... |
| CVE-2025-2341 | LOW | 3.1 | 0.3% | Mar 16, 2025 | A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some... |
| CVE-2025-1624 | LOW | 3.5 | 0.2% | Mar 16, 2025 | The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul... |
| CVE-2025-1623 | LOW | 3.5 | 0.2% | Mar 16, 2025 | The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul... |
| CVE-2025-1622 | LOW | 3.5 | 0.2% | Mar 16, 2025 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now