2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24309 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-24301 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-23420 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-23414 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-23409 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-23240 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-22835 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-21084 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through t... |
| CVE-2025-20626 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-20091 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-1639 | HIGH | 8.8 | 0.9% | Mar 4, 2025 | The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation ... |
| CVE-2025-1321 | HIGH | 8.8 | 0.4% | Mar 4, 2025 | The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode... |
| CVE-2025-0587 | HIGH | 7.8 | 0.2% | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through i... |
| CVE-2025-1899 | HIGH | 7.5 | 0.7% | Mar 4, 2025 | A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability... |
| CVE-2025-1898 | HIGH | 7.5 | 0.8% | Mar 4, 2025 | A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown func... |
| CVE-2025-1897 | HIGH | 7.5 | 1.1% | Mar 4, 2025 | A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects som... |
| CVE-2025-1896 | HIGH | 7.5 | 0.8% | Mar 4, 2025 | A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code... |
| CVE-2025-1895 | HIGH | 7.5 | 0.8% | Mar 4, 2025 | A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of th... |
| CVE-2025-1893 | HIGH | 7.5 | 0.7% | Mar 4, 2025 | A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is... |
| CVE-2025-27220 | HIGH | 7.5 | 0.7% | Mar 4, 2025 | In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#es... |
| CVE-2025-27219 | HIGH | 7.5 | 0.8% | Mar 4, 2025 | In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Ser... |
| CVE-2025-1882 | HIGH | 7 | 0.2% | Mar 3, 2025 | A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue i... |
| CVE-2025-27501 | HIGH | 8.6 | 0.4% | Mar 3, 2025 | OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin p... |
| CVE-2025-25967 | HIGH | 8.8 | 0.5% | Mar 3, 2025 | Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authen... |
| CVE-2025-1877 | HIGH | 7.5 | 1.0% | Mar 3, 2025 | A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now