2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27423 | HIGH | 7.1 | 20.8% | Mar 3, 2025 | Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing an... |
| CVE-2025-27422 | HIGH | 7.5 | 0.4% | Mar 3, 2025 | FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker regis... |
| CVE-2025-27421 | HIGH | 7.5 | 0.4% | Mar 3, 2025 | Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in t... |
| CVE-2025-25301 | HIGH | 7.5 | 0.5% | Mar 3, 2025 | Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query par... |
| CVE-2025-0678 | HIGH | 7.8 | 0.3% | Mar 3, 2025 | A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled pa... |
| CVE-2025-0289 | HIGH | 7.8 | 0.3% | Mar 3, 2025 | Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not... |
| CVE-2025-0288 | HIGH | 7.8 | 0.5% | Mar 3, 2025 | Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by t... |
| CVE-2025-0286 | HIGH | 8.4 | 0.4% | Mar 3, 2025 | Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is cau... |
| CVE-2025-0285 | HIGH | 7.8 | 0.3% | Mar 3, 2025 | Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is c... |
| CVE-2025-27419 | HIGH | 7.5 | 0.5% | Mar 3, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS... |
| CVE-2025-25185 | HIGH | 7.5 | 0.6% | Mar 3, 2025 | GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not prope... |
| CVE-2025-1801 | HIGH | 8.1 | 0.3% | Mar 3, 2025 | A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concu... |
| CVE-2025-1125 | HIGH | 7.8 | 0.4% | Mar 3, 2025 | When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesyste... |
| CVE-2025-0689 | HIGH | 7.8 | 0.4% | Mar 3, 2025 | When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to alloc... |
| CVE-2025-27279 | HIGH | 7.1 | 0.2% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lynk Flashfader fl... |
| CVE-2025-27278 | HIGH | 7.1 | 0.2% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Ghedini AcuG... |
| CVE-2025-27275 | HIGH | 7.1 | 0.2% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO ... |
| CVE-2025-27271 | HIGH | 7.1 | 0.2% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alberto Cocchiara ... |
| CVE-2025-27269 | HIGH | 7.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anton Aleksandrov ... |
| CVE-2025-27264 | HIGH | 7.5 | 0.7% | Mar 3, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-27263 | HIGH | 8.5 | 0.4% | Mar 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creativeitem Docto... |
| CVE-2025-26999 | HIGH | 8.8 | 0.6% | Mar 3, 2025 | Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communiti... |
| CVE-2025-26988 | HIGH | 7.5 | 0.5% | Mar 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-26967 | HIGH | 8.8 | 0.6% | Mar 3, 2025 | Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allo... |
| CVE-2025-26914 | HIGH | 7.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Insp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now