2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22444 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform... |
| CVE-2025-20105 | HIGH | 8.7 | 0.1% | Mar 10, 2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation ... |
| CVE-2025-20096 | MEDIUM | 5.9 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ... |
| CVE-2025-20073 | LOW | 1.8 | 0.1% | Mar 10, 2026 | Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor... |
| CVE-2025-20068 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati... |
| CVE-2025-20064 | HIGH | 8.7 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation... |
| CVE-2025-20028 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e... |
| CVE-2025-20027 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p... |
| CVE-2025-20005 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv... |
| CVE-2025-70802 | HIGH | 8.4 | 0.2% | Mar 10, 2026 | Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/sh... |
| CVE-2025-70798 | HIGH | 8.4 | 0.2% | Mar 10, 2026 | Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shado... |
| CVE-2025-70244 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup. |
| CVE-2025-66413 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ... |
| CVE-2025-36920 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validatio... |
| CVE-2025-13213 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp... |
| CVE-2025-70251 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup. |
| CVE-2025-70249 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2. |
| CVE-2025-70247 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1. |
| CVE-2025-70246 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ. |
| CVE-2025-70242 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP. |
| CVE-2025-70227 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange. |
| CVE-2025-70129 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate... |
| CVE-2025-70128 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.... |
| CVE-2025-48611 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t... |
| CVE-2025-36227 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now