2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40943 | CRITICAL | 9.6 | 0.5% | Mar 10, 2026 | Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug... |
| CVE-2025-27769 | LOW | 2.6 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC... |
| CVE-2025-13957 | HIGH | 7.5 | 0.7% | Mar 10, 2026 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec... |
| CVE-2025-13902 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co... |
| CVE-2025-13901 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine... |
| CVE-2025-11739 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr... |
| CVE-2025-36173 | MEDIUM | 6.1 | 0.1% | Mar 10, 2026 | Affected Product(s)Version(s)InfoSphere Data Architect9.2.1 |
| CVE-2025-36105 | MEDIUM | 4.4 | 0.1% | Mar 10, 2026 | IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s... |
| CVE-2025-2399 | MEDIUM | 5.9 | 0.6% | Mar 10, 2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri... |
| CVE-2025-11158 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric... |
| CVE-2025-70973 | MEDIUM | 4.8 | 0.2% | Mar 9, 2026 | ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated... |
| CVE-2025-70028 | HIGH | 7.5 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov... |
| CVE-2025-15603 | — | — | — | Mar 9, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b... |
| CVE-2025-70031 | HIGH | 8.8 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. |
| CVE-2025-70030 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd... |
| CVE-2025-68402 | HIGH | 8.2 | 0.3% | Mar 9, 2026 | FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c... |
| CVE-2025-62166 | HIGH | 7.5 | 0.4% | Mar 9, 2026 | FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication... |
| CVE-2025-70032 | MEDIUM | 6.1 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. |
| CVE-2025-70039 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag... |
| CVE-2025-70038 | HIGH | 8.8 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw... |
| CVE-2025-70034 | HIGH | 7.5 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0. |
| CVE-2025-70033 | MEDIUM | 5.4 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed ... |
| CVE-2025-70037 | MEDIUM | 6.1 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This a... |
| CVE-2025-15568 | HIGH | 8 | 1.4% | Mar 9, 2026 | A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a... |
| CVE-2025-70060 | MEDIUM | 5.4 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now