2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62184 | LOW | 3.4 | 0.3% | Mar 31, 2026 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf... |
| CVE-2025-14213 | HIGH | 8.3 | 1.0% | Mar 31, 2026 | Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack... |
| CVE-2025-15618 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online... |
| CVE-2025-41357 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
| CVE-2025-41356 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
| CVE-2025-41355 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t... |
| CVE-2025-10559 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE... |
| CVE-2025-10553 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag... |
| CVE-2025-10551 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat... |
| CVE-2025-32957 | HIGH | 7.2 | 0.6% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ... |
| CVE-2025-66215 | MEDIUM | 6.8 | 0.2% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-66038 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com... |
| CVE-2025-66037 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p... |
| CVE-2025-49010 | MEDIUM | 6.8 | 0.1% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-3716 | MEDIUM | 5.3 | 0.2% | Mar 30, 2026 | User enumeration in ESET Protect (on-prem) via Response Timing. |
| CVE-2025-15379 | CRITICAL | 9.8 | 2.0% | Mar 30, 2026 | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_... |
| CVE-2025-15036 | CRITICAL | 10 | 0.6% | Mar 30, 2026 | A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif... |
| CVE-2025-7741 | LOW | 2.1 | 0.2% | Mar 30, 2026 | Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ... |
| CVE-2025-15604 | CRITICAL | 9.8 | 0.5% | Mar 28, 2026 | Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.... |
| CVE-2025-9497 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This... |
| CVE-2025-15445 | MEDIUM | 5.4 | 0.2% | Mar 28, 2026 | The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c... |
| CVE-2025-12886 | HIGH | 7.2 | 0.2% | Mar 28, 2026 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2025-15612 | HIGH | 8.1 | 0.2% | Mar 27, 2026 | Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k... |
| CVE-2025-15617 | HIGH | 8.1 | 0.4% | Mar 27, 2026 | Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex... |
| CVE-2025-15616 | HIGH | 7.2 | 1.6% | Mar 27, 2026 | Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now