2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2849 | MEDIUM | 5.5 | 0.3% | Mar 27, 2025 | A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxEl... |
| CVE-2025-27793 | MEDIUM | 5.3 | 0.5% | Mar 27, 2025 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-26738 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Inter... |
| CVE-2025-26737 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes City ... |
| CVE-2025-26736 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai Mornin... |
| CVE-2025-26734 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peregrinethemes He... |
| CVE-2025-26732 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware Sto... |
| CVE-2025-26731 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ... |
| CVE-2025-26619 | MEDIUM | 6.1 | 0.3% | Mar 27, 2025 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-22816 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetrendy Power M... |
| CVE-2025-22770 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | Missing Authorization vulnerability in EnvoThemes Envo Multipurpose allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-22673 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | Missing Authorization vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Exploiting Incorrectly C... |
| CVE-2025-22672 | MEDIUM | 4.9 | 0.2% | Mar 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-u... |
| CVE-2025-21871 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix supplicant wait loop OP-TEE suppli... |
| CVE-2025-21870 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Harden loops for looking ... |
| CVE-2025-21868 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SK... |
| CVE-2025-2255 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17... |
| CVE-2025-0811 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.... |
| CVE-2025-31140 | MEDIUM | 6.1 | 26.6% | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page |
| CVE-2025-31139 | MEDIUM | 6.5 | 0.9% | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log |
| CVE-2025-30925 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack ... |
| CVE-2025-30923 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce gift-message-for-woocommerce ... |
| CVE-2025-30922 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simp... |
| CVE-2025-30920 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Po... |
| CVE-2025-30918 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme Struc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now