2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1918 | HIGH | 8.8 | 0.4% | Mar 5, 2025 | Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform ou... |
| CVE-2025-1916 | HIGH | 8.8 | 0.3% | Mar 5, 2025 | Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a... |
| CVE-2025-1915 | HIGH | 8.1 | 0.4% | Mar 5, 2025 | Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.... |
| CVE-2025-1914 | HIGH | 8.8 | 0.4% | Mar 5, 2025 | Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memo... |
| CVE-2025-21092 | HIGH | 7.1 | 0.3% | Mar 5, 2025 | GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in a... |
| CVE-2025-1961 | HIGH | 7.5 | 0.2% | Mar 4, 2025 | A vulnerability has been found in SourceCodester Best Church Management Software 1.1 and classified as critical. Affecte... |
| CVE-2025-25426 | HIGH | 7.2 | 0.4% | Mar 4, 2025 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. |
| CVE-2025-1259 | HIGH | 7.7 | 0.3% | Mar 4, 2025 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been ... |
| CVE-2025-1080 | HIGH | 7.8 | 0.3% | Mar 4, 2025 | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit... |
| CVE-2025-27111 | HIGH | 7.5 | 0.7% | Mar 4, 2025 | Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sen... |
| CVE-2025-23368 | HIGH | 8.1 | 0.9% | Mar 4, 2025 | A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multipl... |
| CVE-2025-1424 | HIGH | 8.6 | 0.2% | Mar 4, 2025 | A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if the... |
| CVE-2025-1943 | HIGH | 8.2 | 0.4% | Mar 4, 2025 | Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-1940 | HIGH | 7.1 | 0.2% | Mar 4, 2025 | A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used... |
| CVE-2025-1937 | HIGH | 7.5 | 0.5% | Mar 4, 2025 | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7... |
| CVE-2025-1936 | HIGH | 7.3 | 0.4% | Mar 4, 2025 | jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retri... |
| CVE-2025-1933 | HIGH | 7.6 | 0.3% | Mar 4, 2025 | On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can poten... |
| CVE-2025-1932 | HIGH | 8.1 | 0.4% | Mar 4, 2025 | An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Onl... |
| CVE-2025-1931 | HIGH | 7.5 | 0.5% | Mar 4, 2025 | It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potenti... |
| CVE-2025-1930 | HIGH | 8.8 | 0.4% | Mar 4, 2025 | On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the... |
| CVE-2025-1925 | HIGH | 7.5 | 0.7% | Mar 4, 2025 | A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the functi... |
| CVE-2025-22225 | HIGH | 8.2 | 1.0% | Mar 4, 2025 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trig... |
| CVE-2025-22224 | HIGH | 8.2 | 1.5% | Mar 4, 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds w... |
| CVE-2025-0360 | HIGH | 7.8 | 0.1% | Mar 4, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi... |
| CVE-2025-1306 | HIGH | 8.8 | 0.5% | Mar 4, 2025 | The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now