2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27400 | LOW | 2.9 | 0.2% | Feb 28, 2025 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2025-22274 | LOW | 2 | 0.4% | Feb 28, 2025 | It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page.... |
| CVE-2025-22272 | LOW | 2.1 | 0.4% | Feb 28, 2025 | In the "/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg" endpoint, it is possible to inject code in the "modalDlgMsgIn... |
| CVE-2025-0914 | LOW | 3.8 | 0.2% | Feb 27, 2025 | An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users ... |
| CVE-2025-0759 | LOW | 3.3 | 0.1% | Feb 27, 2025 | IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared reso... |
| CVE-2025-26698 | LOW | 2.7 | 0.2% | Feb 26, 2025 | Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, maliciou... |
| CVE-2025-0760 | LOW | 2.7 | 0.2% | Feb 26, 2025 | A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials du... |
| CVE-2025-22211 | LOW | 3.4 | 0.3% | Feb 25, 2025 | A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attacke... |
| CVE-2025-25878 | LOW | 3.8 | 0.3% | Feb 21, 2025 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ... |
| CVE-2025-25877 | LOW | 3.8 | 0.3% | Feb 21, 2025 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ... |
| CVE-2025-25299 | LOW | 2.3 | 0.6% | Feb 20, 2025 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Sit... |
| CVE-2025-24806 | LOW | 2.3 | 0.4% | Feb 19, 2025 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2025-25300 | LOW | 1.3 | 0.4% | Feb 18, 2025 | smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner ... |
| CVE-2025-25899 | LOW | 3.5 | 0.3% | Feb 13, 2025 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIp... |
| CVE-2025-0692 | LOW | 3.5 | 0.3% | Feb 13, 2025 | The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, whi... |
| CVE-2025-1207 | LOW | 3.1 | 0.3% | Feb 12, 2025 | A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2025-1243 | LOW | 2 | 0.1% | Feb 12, 2025 | The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when th... |
| CVE-2025-24432 | LOW | 3.7 | 0.4% | Feb 11, 2025 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec... |
| CVE-2025-24430 | LOW | 3.7 | 0.4% | Feb 11, 2025 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec... |
| CVE-2025-24429 | LOW | 3.5 | 0.5% | Feb 11, 2025 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Ac... |
| CVE-2025-21337 | LOW | 3.3 | 0.5% | Feb 11, 2025 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2025-1180 | LOW | 3.1 | 0.6% | Feb 11, 2025 | A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_... |
| CVE-2025-23191 | LOW | 3.1 | 0.2% | Feb 11, 2025 | Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host heade... |
| CVE-2025-1152 | LOW | 3.7 | 0.6% | Feb 10, 2025 | A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the f... |
| CVE-2025-1151 | LOW | 3.1 | 0.6% | Feb 10, 2025 | A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now