2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27277 | HIGH | 7.1 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v... |
| CVE-2025-27276 | HIGH | 8.8 | 0.2% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows ... |
| CVE-2025-27272 | HIGH | 7.5 | 0.7% | Feb 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-25279 | HIGH | 7.5 | 20.8% | Feb 24, 2025 | Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate boa... |
| CVE-2025-1412 | HIGH | 8.8 | 0.2% | Feb 24, 2025 | Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to ... |
| CVE-2025-1606 | HIGH | 7.5 | 0.6% | Feb 24, 2025 | A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerab... |
| CVE-2025-22632 | HIGH | 7.1 | 0.2% | Feb 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalsoft WooComme... |
| CVE-2025-22631 | HIGH | 7.1 | 0.2% | Feb 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Au... |
| CVE-2025-1594 | HIGH | 8.8 | 0.5% | Feb 23, 2025 | A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_searc... |
| CVE-2025-1590 | HIGH | 7.2 | 0.4% | Feb 23, 2025 | A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an un... |
| CVE-2025-1587 | HIGH | 7.8 | 0.3% | Feb 23, 2025 | A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This i... |
| CVE-2025-1578 | HIGH | 7.5 | 0.4% | Feb 23, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This af... |
| CVE-2025-27012 | HIGH | 8.8 | 0.2% | Feb 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce ... |
| CVE-2025-26774 | HIGH | 7.1 | 0.2% | Feb 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Respons... |
| CVE-2025-26760 | HIGH | 7.5 | 0.6% | Feb 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26757 | HIGH | 7.5 | 0.5% | Feb 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26756 | HIGH | 7.1 | 0.2% | Feb 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic t... |
| CVE-2025-0957 | HIGH | 7.2 | 0.5% | Feb 22, 2025 | The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a... |
| CVE-2025-21704 | HIGH | 7.8 | 0.3% | Feb 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size be... |
| CVE-2025-27109 | HIGH | 7.3 | 0.3% | Feb 21, 2025 | solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions... |
| CVE-2025-27106 | HIGH | 8.8 | 1.9% | Feb 21, 2025 | binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-... |
| CVE-2025-27104 | HIGH | 7.5 | 0.4% | Feb 21, 2025 | vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the i... |
| CVE-2025-26622 | HIGH | 7.5 | 0.3% | Feb 21, 2025 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate ... |
| CVE-2025-25282 | HIGH | 8.1 | 0.4% | Feb 21, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authentic... |
| CVE-2025-25769 | HIGH | 8 | 0.2% | Feb 21, 2025 | Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/Use... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now