2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25876 | HIGH | 7.2 | 0.4% | Feb 21, 2025 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ... |
| CVE-2025-1546 | HIGH | 7.3 | 2.6% | Feb 21, 2025 | A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critica... |
| CVE-2025-1403 | HIGH | 8.6 | 0.7% | Feb 21, 2025 | Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted Q... |
| CVE-2025-26013 | HIGH | 8.2 | 0.4% | Feb 21, 2025 | An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component. |
| CVE-2025-1538 | HIGH | 8.8 | 1.3% | Feb 21, 2025 | A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function... |
| CVE-2025-1536 | HIGH | 7.3 | 2.5% | Feb 21, 2025 | A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical... |
| CVE-2025-1535 | HIGH | 7.3 | 0.4% | Feb 21, 2025 | A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This... |
| CVE-2025-1471 | HIGH | 7.8 | 0.2% | Feb 21, 2025 | In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string co... |
| CVE-2025-0728 | HIGH | 7.5 | 0.7% | Feb 21, 2025 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer un... |
| CVE-2025-0727 | HIGH | 7.5 | 0.7% | Feb 21, 2025 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer un... |
| CVE-2025-0726 | HIGH | 7.5 | 0.7% | Feb 21, 2025 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of s... |
| CVE-2025-27088 | HIGH | 8.2 | 0.5% | Feb 20, 2025 | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulner... |
| CVE-2025-25679 | HIGH | 8 | 0.3% | Feb 20, 2025 | Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSe... |
| CVE-2025-22973 | HIGH | 7.5 | 0.4% | Feb 20, 2025 | An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function ... |
| CVE-2025-27098 | HIGH | 7.5 | 0.3% | Feb 20, 2025 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgra... |
| CVE-2025-27097 | HIGH | 7.5 | 0.4% | Feb 20, 2025 | GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgra... |
| CVE-2025-0352 | HIGH | 8.7 | 0.3% | Feb 20, 2025 | Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify reque... |
| CVE-2025-26618 | HIGH | 7 | 0.5% | Feb 20, 2025 | Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirem... |
| CVE-2025-27091 | HIGH | 7.5 | 0.6% | Feb 20, 2025 | OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding fun... |
| CVE-2025-26305 | HIGH | 8.2 | 0.4% | Feb 20, 2025 | A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows at... |
| CVE-2025-26304 | HIGH | 8.2 | 0.4% | Feb 20, 2025 | A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8. |
| CVE-2025-0161 | HIGH | 7.8 | 0.2% | Feb 20, 2025 | IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrar... |
| CVE-2025-21105 | HIGH | 7.8 | 0.1% | Feb 20, 2025 | Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user... |
| CVE-2025-26856 | HIGH | 7.2 | 1.2% | Feb 20, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa... |
| CVE-2025-1492 | HIGH | 7.5 | 0.3% | Feb 20, 2025 | Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now