2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1293 | HIGH | 8.2 | 0.3% | Feb 20, 2025 | Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentiall... |
| CVE-2025-27092 | HIGH | 7.5 | 0.6% | Feb 19, 2025 | GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path... |
| CVE-2025-25944 | HIGH | 7.3 | 0.2% | Feb 19, 2025 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom... |
| CVE-2025-25943 | HIGH | 7.8 | 0.2% | Feb 19, 2025 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2At... |
| CVE-2025-0624 | HIGH | 7.6 | 1.4% | Feb 19, 2025 | A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copie... |
| CVE-2025-0893 | HIGH | 7.8 | 0.1% | Feb 19, 2025 | Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability. |
| CVE-2025-24965 | HIGH | 8.5 | 0.5% | Feb 19, 2025 | crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could ... |
| CVE-2025-1426 | HIGH | 8.8 | 0.6% | Feb 19, 2025 | Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially... |
| CVE-2025-1006 | HIGH | 8.8 | 0.5% | Feb 19, 2025 | Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap... |
| CVE-2025-0999 | HIGH | 8.8 | 0.6% | Feb 19, 2025 | Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit hea... |
| CVE-2025-1464 | HIGH | 7.3 | 0.4% | Feb 19, 2025 | A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204.... |
| CVE-2025-1075 | HIGH | 7.5 | 0.3% | Feb 19, 2025 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (... |
| CVE-2025-1135 | HIGH | 7.2 | 0.7% | Feb 19, 2025 | A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploi... |
| CVE-2025-1134 | HIGH | 7.2 | 0.7% | Feb 19, 2025 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit... |
| CVE-2025-1133 | HIGH | 7.2 | 0.6% | Feb 19, 2025 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit... |
| CVE-2025-1132 | HIGH | 8.8 | 0.5% | Feb 19, 2025 | A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within th... |
| CVE-2025-1441 | HIGH | 8.8 | 0.2% | Feb 19, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-1448 | HIGH | 7.3 | 2.9% | Feb 19, 2025 | A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This ... |
| CVE-2025-27113 | HIGH | 7.5 | 1.0% | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. |
| CVE-2025-25475 | HIGH | 7.5 | 0.5% | Feb 18, 2025 | A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial ... |
| CVE-2025-24928 | HIGH | 7.7 | 0.4% | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To ... |
| CVE-2025-25895 | HIGH | 8 | 1.0% | Feb 18, 2025 | An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulner... |
| CVE-2025-25894 | HIGH | 8 | 1.0% | Feb 18, 2025 | An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters.... |
| CVE-2025-25893 | HIGH | 8 | 1.0% | Feb 18, 2025 | An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, e... |
| CVE-2025-26616 | HIGH | 7.5 | 0.6% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now