2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10736 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for... |
| CVE-2025-71276 | MEDIUM | 6.1 | 0.1% | Mar 22, 2026 | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. |
| CVE-2025-14037 | HIGH | 8.1 | 0.2% | Mar 21, 2026 | The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi... |
| CVE-2025-13910 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA... |
| CVE-2025-63261 | HIGH | 7.8 | 1.0% | Mar 20, 2026 | AWStats 8.0 is vulnerable to Command Injection via the open function |
| CVE-2025-55988 | HIGH | 7.2 | 0.9% | Mar 20, 2026 | An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire... |
| CVE-2025-63260 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-U... |
| CVE-2025-62846 | MEDIUM | 6.7 | 0.2% | Mar 20, 2026 | An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th... |
| CVE-2025-62845 | MEDIUM | 6.7 | 0.2% | Mar 20, 2026 | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l... |
| CVE-2025-62844 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c... |
| CVE-2025-62843 | MEDIUM | 6.8 | 0.3% | Mar 20, 2026 | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. ... |
| CVE-2025-59383 | CRITICAL | 9.1 | 0.3% | Mar 20, 2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi... |
| CVE-2025-15608 | CRITICAL | 9.8 | 0.6% | Mar 20, 2026 | This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ... |
| CVE-2025-15607 | CRITICAL | 9.8 | 2.0% | Mar 20, 2026 | A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo... |
| CVE-2025-67260 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln... |
| CVE-2025-46597 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | Bitcoin Core 0.13.0 through 29.x has an integer overflow. |
| CVE-2025-46598 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. |
| CVE-2025-67115 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor... |
| CVE-2025-67114 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng... |
| CVE-2025-67113 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be... |
| CVE-2025-67112 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F... |
| CVE-2025-69720 | HIGH | 7.8 | 0.4% | Mar 19, 2026 | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog... |
| CVE-2025-71260 | HIGH | 8.8 | 34.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ... |
| CVE-2025-71259 | HIGH | 7.1 | 12.9% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
| CVE-2025-71258 | HIGH | 7.1 | 17.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now