2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15484 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant... |
| CVE-2025-71282 | HIGH | 8.7 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ... |
| CVE-2025-71281 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in... |
| CVE-2025-71280 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu... |
| CVE-2025-71279 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may... |
| CVE-2025-71278 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O... |
| CVE-2025-13855 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could... |
| CVE-2025-62184 | LOW | 3.4 | 0.3% | Mar 31, 2026 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf... |
| CVE-2025-14213 | HIGH | 8.3 | 1.0% | Mar 31, 2026 | Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack... |
| CVE-2025-15618 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online... |
| CVE-2025-41357 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
| CVE-2025-41356 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to... |
| CVE-2025-41355 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t... |
| CVE-2025-10559 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE... |
| CVE-2025-10553 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag... |
| CVE-2025-10551 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat... |
| CVE-2025-32957 | HIGH | 7.2 | 0.6% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ... |
| CVE-2025-66215 | MEDIUM | 6.8 | 0.2% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-66038 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com... |
| CVE-2025-66037 | MEDIUM | 6.8 | 0.3% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p... |
| CVE-2025-49010 | MEDIUM | 6.8 | 0.1% | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t... |
| CVE-2025-3716 | MEDIUM | 5.3 | 0.2% | Mar 30, 2026 | User enumeration in ESET Protect (on-prem) via Response Timing. |
| CVE-2025-15379 | CRITICAL | 10 | 2.0% | Mar 30, 2026 | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_... |
| CVE-2025-15036 | CRITICAL | 10 | 0.6% | Mar 30, 2026 | A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif... |
| CVE-2025-7741 | LOW | 2.1 | 0.2% | Mar 30, 2026 | Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now