2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67113 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be... |
| CVE-2025-67112 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F... |
| CVE-2025-69720 | HIGH | 7.8 | 0.4% | Mar 19, 2026 | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in prog... |
| CVE-2025-71260 | HIGH | 8.8 | 34.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in ... |
| CVE-2025-71259 | HIGH | 7.1 | 12.9% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
| CVE-2025-71258 | HIGH | 7.1 | 17.4% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in ... |
| CVE-2025-71257 | CRITICAL | 9.1 | 5.2% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope... |
| CVE-2025-14716 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue... |
| CVE-2025-68836 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table... |
| CVE-2025-67618 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Bro... |
| CVE-2025-62043 | MEDIUM | 6.5 | 0.1% | Mar 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all... |
| CVE-2025-60237 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from... |
| CVE-2025-60233 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n... |
| CVE-2025-53222 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-... |
| CVE-2025-50001 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-32223 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ... |
| CVE-2025-36051 | MEDIUM | 5.5 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th... |
| CVE-2025-15051 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2025-13995 | MEDIUM | 5 | 0.2% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna... |
| CVE-2025-15031 | CRITICAL | 9.1 | 0.9% | Mar 18, 2026 | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a... |
| CVE-2025-58112 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v... |
| CVE-2025-71270 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ... |
| CVE-2025-71269 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro... |
| CVE-2025-71268 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe... |
| CVE-2025-67830 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now