2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71257 | CRITICAL | 9.1 | 5.2% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope... |
| CVE-2025-14716 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue... |
| CVE-2025-68836 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table... |
| CVE-2025-67618 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro... |
| CVE-2025-62043 | MEDIUM | 6.5 | 0.1% | Mar 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all... |
| CVE-2025-60237 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from... |
| CVE-2025-60233 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n... |
| CVE-2025-53222 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-... |
| CVE-2025-50001 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-32223 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ... |
| CVE-2025-36051 | MEDIUM | 5.5 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th... |
| CVE-2025-15051 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2025-13995 | MEDIUM | 5 | 0.2% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna... |
| CVE-2025-15031 | CRITICAL | 9.1 | 0.9% | Mar 18, 2026 | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a... |
| CVE-2025-58112 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v... |
| CVE-2025-71270 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ... |
| CVE-2025-71269 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro... |
| CVE-2025-71268 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe... |
| CVE-2025-67830 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. |
| CVE-2025-67829 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. |
| CVE-2025-55046 | HIGH | 8.1 | 0.1% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s... |
| CVE-2025-55045 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information... |
| CVE-2025-55044 | HIGH | 8.8 | 0.1% | Mar 18, 2026 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra... |
| CVE-2025-55043 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m... |
| CVE-2025-55041 | HIGH | 8 | 0.1% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now