2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0182 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue ar... |
| CVE-2025-1385 | HIGH | 7.5 | 0.4% | Mar 20, 2025 | When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows ... |
| CVE-2025-22228 | HIGH | 7.4 | 0.6% | Mar 20, 2025 | BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters ... |
| CVE-2025-1770 | HIGH | 8.8 | 0.8% | Mar 20, 2025 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In... |
| CVE-2025-27787 | HIGH | 7.5 | 0.7% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.... |
| CVE-2025-27785 | HIGH | 7.5 | 0.5% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `... |
| CVE-2025-27784 | HIGH | 7.5 | 0.5% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `... |
| CVE-2025-27777 | HIGH | 7.5 | 0.4% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `mod... |
| CVE-2025-2476 | HIGH | 8.8 | 0.8% | Mar 19, 2025 | Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-27415 | HIGH | 7.5 | 0.4% | Mar 19, 2025 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a ser... |
| CVE-2025-29924 | HIGH | 7.5 | 0.4% | Mar 19, 2025 | XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get... |
| CVE-2025-30154 | HIGH | 8.6 | 2.3% | Mar 19, 2025 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2... |
| CVE-2025-30153 | HIGH | 7.5 | 0.5% | Mar 19, 2025 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/for... |
| CVE-2025-2324 | HIGH | 8.8 | 0.2% | Mar 19, 2025 | Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP mo... |
| CVE-2025-1758 | HIGH | 8.8 | 4.8% | Mar 19, 2025 | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster... |
| CVE-2025-30236 | HIGH | 8.6 | 0.3% | Mar 19, 2025 | Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skippin... |
| CVE-2025-1232 | HIGH | 8.8 | 1.9% | Mar 19, 2025 | The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which co... |
| CVE-2025-30234 | HIGH | 8.3 | 0.2% | Mar 19, 2025 | SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32... |
| CVE-2025-30140 | HIGH | 7.5 | 0.3% | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It ... |
| CVE-2025-30142 | HIGH | 8.1 | 0.3% | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address ver... |
| CVE-2025-30141 | HIGH | 7.5 | 0.3% | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream.... |
| CVE-2025-29907 | HIGH | 7.5 | 0.6% | Mar 18, 2025 | jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage me... |
| CVE-2025-24801 | HIGH | 8.8 | 17.5% | Mar 18, 2025 | GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.p... |
| CVE-2025-26137 | HIGH | 7.5 | 0.4% | Mar 18, 2025 | Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attac... |
| CVE-2025-27688 | HIGH | 7.8 | 0.1% | Mar 18, 2025 | Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now