2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70024 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk... |
| CVE-2025-66956 | CRITICAL | 9.9 | 0.6% | Mar 11, 2026 | Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t... |
| CVE-2025-70082 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio... |
| CVE-2025-68623 | HIGH | 8.8 | 0.1% | Mar 11, 2026 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file dur... |
| CVE-2025-67041 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse... |
| CVE-2025-67039 | CRITICAL | 9.1 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe... |
| CVE-2025-67038 | CRITICAL | 9.8 | 1.1% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ... |
| CVE-2025-67037 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunne... |
| CVE-2025-67036 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying th... |
| CVE-2025-67035 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS ... |
| CVE-2025-67034 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name"... |
| CVE-2025-12555 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-14513 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ... |
| CVE-2025-13929 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-13690 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ... |
| CVE-2025-12704 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9... |
| CVE-2025-12697 | MEDIUM | 4.4 | 0.3% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-12690 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF... |
| CVE-2025-12576 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18... |
| CVE-2025-70330 | LOW | 3.3 | 0.2% | Mar 11, 2026 | Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify... |
| CVE-2025-70027 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This ... |
| CVE-2025-67298 | HIGH | 8.1 | 0.2% | Mar 11, 2026 | An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and ... |
| CVE-2025-13067 | HIGH | 8.8 | 0.5% | Mar 11, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in... |
| CVE-2025-12473 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ... |
| CVE-2025-22850 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now