2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23397 | HIGH | 7.8 | 0.2% | Mar 11, 2025 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualizat... |
| CVE-2025-23396 | HIGH | 7.8 | 0.2% | Mar 11, 2025 | A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualizat... |
| CVE-2025-2176 | HIGH | 7.5 | 0.6% | Mar 11, 2025 | A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim... |
| CVE-2025-27912 | HIGH | 8.8 | 0.2% | Mar 11, 2025 | An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) E... |
| CVE-2025-2190 | HIGH | 8.1 | 0.3% | Mar 11, 2025 | The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code inject... |
| CVE-2025-2174 | HIGH | 7.5 | 0.8% | Mar 11, 2025 | A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability i... |
| CVE-2025-2173 | HIGH | 7.5 | 0.6% | Mar 11, 2025 | A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_s... |
| CVE-2025-26705 | HIGH | 7.5 | 0.3% | Mar 11, 2025 | Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro... |
| CVE-2025-26702 | HIGH | 7.5 | 0.4% | Mar 11, 2025 | Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from... |
| CVE-2025-2169 | HIGH | 7.3 | 0.5% | Mar 11, 2025 | The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execut... |
| CVE-2025-27434 | HIGH | 8.8 | 0.4% | Mar 11, 2025 | Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicio... |
| CVE-2025-26661 | HIGH | 8.8 | 0.4% | Mar 11, 2025 | Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels t... |
| CVE-2025-1828 | HIGH | 8.8 | 0.4% | Mar 11, 2025 | Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptog... |
| CVE-2025-27610 | HIGH | 7.5 | 1.1% | Mar 10, 2025 | Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack:... |
| CVE-2025-27910 | HIGH | 8 | 0.2% | Mar 10, 2025 | tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This ... |
| CVE-2025-25907 | HIGH | 8.8 | 0.2% | Mar 10, 2025 | tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulner... |
| CVE-2025-2137 | HIGH | 8.8 | 0.4% | Mar 10, 2025 | Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memo... |
| CVE-2025-2136 | HIGH | 8.8 | 0.3% | Mar 10, 2025 | Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit hea... |
| CVE-2025-2135 | HIGH | 8.8 | 6.4% | Mar 10, 2025 | Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-1920 | HIGH | 8.8 | 0.3% | Mar 10, 2025 | Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-27913 | HIGH | 7.5 | 0.2% | Mar 10, 2025 | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health... |
| CVE-2025-27616 | HIGH | 8.5 | 0.2% | Mar 10, 2025 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions... |
| CVE-2025-27615 | HIGH | 8.2 | 0.5% | Mar 10, 2025 | umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. Th... |
| CVE-2025-26696 | HIGH | 7 | 0.3% | Mar 10, 2025 | Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an Ope... |
| CVE-2025-22603 | HIGH | 8.1 | 0.5% | Mar 10, 2025 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now