2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25382 | HIGH | 7.5 | 0.3% | Mar 10, 2025 | An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitraril... |
| CVE-2025-26933 | HIGH | 7.5 | 0.5% | Mar 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-25614 | HIGH | 8.8 | 0.7% | Mar 10, 2025 | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the pers... |
| CVE-2025-2153 | HIGH | 8.1 | 0.5% | Mar 10, 2025 | A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the... |
| CVE-2025-2151 | HIGH | 8.8 | 0.6% | Mar 10, 2025 | A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects t... |
| CVE-2025-2148 | HIGH | 7.5 | 0.4% | Mar 10, 2025 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is th... |
| CVE-2025-2147 | HIGH | 7.5 | 0.6% | Mar 10, 2025 | A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management Sys... |
| CVE-2025-27256 | HIGH | 8.3 | 0.3% | Mar 10, 2025 | Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentic... |
| CVE-2025-27255 | HIGH | 8 | 0.1% | Mar 10, 2025 | Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user... |
| CVE-2025-27254 | HIGH | 8 | 0.2% | Mar 10, 2025 | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's s... |
| CVE-2025-2132 | HIGH | 7.2 | 0.4% | Mar 9, 2025 | A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/i... |
| CVE-2025-2126 | HIGH | 8.8 | 9.4% | Mar 9, 2025 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects som... |
| CVE-2025-2121 | HIGH | 8.8 | 0.9% | Mar 9, 2025 | A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an u... |
| CVE-2025-2118 | HIGH | 7.3 | 0.5% | Mar 9, 2025 | A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown ... |
| CVE-2025-27822 | HIGH | 7.5 | 0.3% | Mar 7, 2025 | An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily swit... |
| CVE-2025-2024 | HIGH | 7.8 | 0.4% | Mar 7, 2025 | Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-27607 | HIGH | 8.8 | 1.5% | Mar 7, 2025 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger ... |
| CVE-2025-27604 | HIGH | 7.5 | 0.3% | Mar 7, 2025 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the ... |
| CVE-2025-0162 | HIGH | 7.1 | 0.5% | Mar 7, 2025 | IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processin... |
| CVE-2025-27597 | HIGH | 8.9 | 0.6% | Mar 7, 2025 | Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnera... |
| CVE-2025-1887 | HIGH | 7.1 | 0.3% | Mar 7, 2025 | SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an... |
| CVE-2025-1886 | HIGH | 7.1 | 0.3% | Mar 7, 2025 | Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated a... |
| CVE-2025-26331 | HIGH | 7.8 | 0.6% | Mar 7, 2025 | Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injectio... |
| CVE-2025-1309 | HIGH | 8.8 | 0.4% | Mar 7, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-27795 | HIGH | 7.5 | 0.4% | Mar 7, 2025 | ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now