2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25589 | HIGH | 8.1 | 0.4% | Mar 18, 2025 | An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.0... |
| CVE-2025-30117 | HIGH | 7.3 | 0.3% | Mar 18, 2025 | An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Dat... |
| CVE-2025-30116 | HIGH | 7.5 | 0.5% | Mar 18, 2025 | An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Liv... |
| CVE-2025-30111 | HIGH | 7.5 | 0.4% | Mar 18, 2025 | On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that a... |
| CVE-2025-30107 | HIGH | 7.5 | 0.3% | Mar 18, 2025 | On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by u... |
| CVE-2025-25585 | HIGH | 7.3 | 0.3% | Mar 18, 2025 | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorize... |
| CVE-2025-30106 | HIGH | 8.8 | 0.3% | Mar 18, 2025 | On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. Th... |
| CVE-2025-2450 | HIGH | 8.8 | 0.5% | Mar 18, 2025 | NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2025-2449 | HIGH | 8.8 | 30.8% | Mar 18, 2025 | NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2025-25500 | HIGH | 7.5 | 0.7% | Mar 18, 2025 | An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a l... |
| CVE-2025-2493 | HIGH | 7.5 | 0.5% | Mar 18, 2025 | Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulat... |
| CVE-2025-1468 | HIGH | 7.5 | 0.6% | Mar 18, 2025 | An unauthenticated remote attacker can gain access to sensitive information including authentication information when us... |
| CVE-2025-25220 | HIGH | 8.8 | 1.0% | Mar 18, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver... |
| CVE-2025-24306 | HIGH | 7.2 | 1.0% | Mar 18, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver... |
| CVE-2025-0755 | HIGH | 7.5 | 0.7% | Mar 18, 2025 | The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing ... |
| CVE-2025-2262 | HIGH | 7.3 | 0.4% | Mar 18, 2025 | The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vu... |
| CVE-2025-2471 | HIGH | 8.8 | 0.4% | Mar 18, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unkno... |
| CVE-2025-2419 | HIGH | 7.5 | 0.4% | Mar 17, 2025 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affec... |
| CVE-2025-2398 | HIGH | 8.6 | 0.5% | Mar 17, 2025 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 2... |
| CVE-2025-29910 | HIGH | 7.5 | 0.5% | Mar 17, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2025-2392 | HIGH | 7.2 | 0.5% | Mar 17, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling Syst... |
| CVE-2025-2389 | HIGH | 7.2 | 0.5% | Mar 17, 2025 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by ... |
| CVE-2025-2388 | HIGH | 7.3 | 0.5% | Mar 17, 2025 | A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is ... |
| CVE-2025-26125 | HIGH | 7.3 | 0.5% | Mar 17, 2025 | An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete fi... |
| CVE-2025-22473 | HIGH | 7.8 | 0.7% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now