2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70024CRITICAL9.8An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk...
CVE-2025-66956CRITICAL9.9Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t...
CVE-2025-70082CRITICAL9.8An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio...
CVE-2025-68623HIGH8.8In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file dur...
CVE-2025-67041CRITICAL9.8An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse...
CVE-2025-67039CRITICAL9.1An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe...
CVE-2025-67038CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ...
CVE-2025-67037HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunne...
CVE-2025-67036HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying th...
CVE-2025-67035CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS ...
CVE-2025-67034HIGH8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name"...
CVE-2025-12555MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-14513HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-13929HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-13690MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-12704MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9...
CVE-2025-12697MEDIUM4.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-12690HIGH7.8Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF...
CVE-2025-12576MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18...
CVE-2025-70330LOW3.3Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify...
CVE-2025-70027HIGH7.5An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This ...
CVE-2025-67298HIGH8.1An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and ...
CVE-2025-13067HIGH8.8The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in...
CVE-2025-12473MEDIUM6.1The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ...
CVE-2025-22850MEDIUM5.6Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now