2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67829 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. |
| CVE-2025-55046 | HIGH | 8.1 | 0.1% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s... |
| CVE-2025-55045 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information... |
| CVE-2025-55044 | HIGH | 8.8 | 0.1% | Mar 18, 2026 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra... |
| CVE-2025-55043 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m... |
| CVE-2025-55041 | HIGH | 8 | 0.1% | Mar 18, 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc ... |
| CVE-2025-55040 | HIGH | 8.8 | 0.2% | Mar 18, 2026 | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form defi... |
| CVE-2025-41258 | HIGH | 8 | 0.3% | Mar 18, 2026 | LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the se... |
| CVE-2025-71267 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size... |
| CVE-2025-71266 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid... |
| CVE-2025-71265 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang... |
| CVE-2025-12518 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious ... |
| CVE-2025-31703 | LOW | 2.4 | 0.2% | Mar 18, 2026 | A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may g... |
| CVE-2025-15363 | MEDIUM | 5.9 | 0.1% | Mar 18, 2026 | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c... |
| CVE-2025-14031 | HIGH | 7.5 | 0.3% | Mar 17, 2026 | IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.... |
| CVE-2025-14806 | MEDIUM | 5.7 | 0.3% | Mar 17, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an... |
| CVE-2025-15584 | MEDIUM | 6.8 | 0.1% | Mar 17, 2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2025-66633 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-66617 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-66503 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-66342 | HIGH | 7.8 | 0.3% | Mar 17, 2026 | A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigg... |
| CVE-2025-66042 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-66000 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-65119 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2025-64776 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now