2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28096 | MEDIUM | 5.4 | 0.2% | Mar 28, 2025 | OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. |
| CVE-2025-28094 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. |
| CVE-2025-28093 | MEDIUM | 6.3 | 0.2% | Mar 28, 2025 | ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. |
| CVE-2025-28092 | MEDIUM | 6.3 | 0.2% | Mar 28, 2025 | ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. |
| CVE-2025-28254 | MEDIUM | 5.4 | 0.3% | Mar 28, 2025 | Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary c... |
| CVE-2025-2926 | MEDIUM | 5.5 | 0.2% | Mar 28, 2025 | A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache... |
| CVE-2025-2925 | MEDIUM | 5.5 | 0.2% | Mar 28, 2025 | A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the functi... |
| CVE-2025-2924 | MEDIUM | 5.5 | 0.3% | Mar 28, 2025 | A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl... |
| CVE-2025-31164 | MEDIUM | 6.6 | 0.2% | Mar 28, 2025 | heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via c... |
| CVE-2025-31163 | MEDIUM | 6.6 | 0.2% | Mar 28, 2025 | Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_... |
| CVE-2025-31162 | MEDIUM | 6.6 | 0.2% | Mar 28, 2025 | Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation vi... |
| CVE-2025-2921 | MEDIUM | 6.4 | 0.3% | Mar 28, 2025 | A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the... |
| CVE-2025-2916 | MEDIUM | 6.3 | 1.4% | Mar 28, 2025 | A vulnerability, which was classified as critical, has been found in Aishida Call Center System up to 20250314. This iss... |
| CVE-2025-2915 | MEDIUM | 5.5 | 0.3% | Mar 28, 2025 | A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__a... |
| CVE-2025-2913 | MEDIUM | 5.3 | 0.2% | Mar 28, 2025 | A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5... |
| CVE-2025-2912 | MEDIUM | 5.3 | 0.2% | Mar 28, 2025 | A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is t... |
| CVE-2025-31010 | MEDIUM | 4.3 | 0.1% | Mar 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Cross ... |
| CVE-2025-2877 | MEDIUM | 6.5 | 0.4% | Mar 28, 2025 | A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to ... |
| CVE-2025-2865 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web... |
| CVE-2025-2864 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning ... |
| CVE-2025-2860 | MEDIUM | 5.3 | 0.3% | Mar 28, 2025 | SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials t... |
| CVE-2025-1781 | MEDIUM | 6.5 | 0.3% | Mar 28, 2025 | There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML o... |
| CVE-2025-0986 | MEDIUM | 4.4 | 0.1% | Mar 28, 2025 | IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certa... |
| CVE-2025-2911 | MEDIUM | 5.3 | 0.3% | Mar 28, 2025 | Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an atta... |
| CVE-2025-2910 | MEDIUM | 6.9 | 0.4% | Mar 28, 2025 | User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now