2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15604 | CRITICAL | 9.8 | 0.5% | Mar 28, 2026 | Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.... |
| CVE-2025-9497 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This... |
| CVE-2025-15445 | MEDIUM | 5.4 | 0.2% | Mar 28, 2026 | The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c... |
| CVE-2025-12886 | HIGH | 7.2 | 0.2% | Mar 28, 2026 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2025-15612 | HIGH | 8.1 | 0.2% | Mar 27, 2026 | Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k... |
| CVE-2025-15617 | HIGH | 8.1 | 0.4% | Mar 27, 2026 | Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex... |
| CVE-2025-15616 | HIGH | 7.2 | 1.6% | Mar 27, 2026 | Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa... |
| CVE-2025-15615 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i... |
| CVE-2025-15381 | HIGH | 7.1 | 0.3% | Mar 27, 2026 | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p... |
| CVE-2025-69988 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi... |
| CVE-2025-69986 | HIGH | 7.2 | 0.5% | Mar 27, 2026 | A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ... |
| CVE-2025-61190 | MEDIUM | 6.1 | 0.2% | Mar 27, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover ... |
| CVE-2025-13478 | HIGH | 8.4 | 0.3% | Mar 27, 2026 | Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to... |
| CVE-2025-59032 | HIGH | 7.5 | 0.7% | Mar 27, 2026 | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi... |
| CVE-2025-59031 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen... |
| CVE-2025-59028 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica... |
| CVE-2025-12805 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ... |
| CVE-2025-55264 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s... |
| CVE-2025-55263 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i... |
| CVE-2025-55262 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti... |
| CVE-2025-55261 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri... |
| CVE-2025-55277 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us... |
| CVE-2025-55276 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz... |
| CVE-2025-55275 | HIGH | 8.1 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren... |
| CVE-2025-55274 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now