2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15615 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i... |
| CVE-2025-15381 | HIGH | 7.1 | 0.3% | Mar 27, 2026 | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p... |
| CVE-2025-69988 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi... |
| CVE-2025-69986 | HIGH | 7.2 | 0.5% | Mar 27, 2026 | A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ... |
| CVE-2025-61190 | MEDIUM | 6.1 | 0.2% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover ... |
| CVE-2025-13478 | HIGH | 8.4 | 0.3% | Mar 27, 2026 | Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to... |
| CVE-2025-59032 | HIGH | 7.5 | 0.7% | Mar 27, 2026 | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi... |
| CVE-2025-59031 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen... |
| CVE-2025-59028 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica... |
| CVE-2025-12805 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ... |
| CVE-2025-55264 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s... |
| CVE-2025-55263 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i... |
| CVE-2025-55262 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti... |
| CVE-2025-55261 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri... |
| CVE-2025-55277 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us... |
| CVE-2025-55276 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz... |
| CVE-2025-55275 | HIGH | 8.1 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren... |
| CVE-2025-55274 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo... |
| CVE-2025-55273 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca... |
| CVE-2025-55272 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw... |
| CVE-2025-55271 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h... |
| CVE-2025-55270 | CRITICAL | 9.8 | 1.0% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ... |
| CVE-2025-55269 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak... |
| CVE-2025-55268 | MEDIUM | 5.3 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se... |
| CVE-2025-55267 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now