2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53815 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-53517 | — | — | — | Mar 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-69784 | HIGH | 8.8 | 0.2% | Mar 16, 2026 | A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to ... |
| CVE-2025-69783 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust... |
| CVE-2025-62319 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool... |
| CVE-2025-57543 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra... |
| CVE-2025-52649 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ... |
| CVE-2025-52646 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52645 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut... |
| CVE-2025-52644 | HIGH | 8.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ... |
| CVE-2025-52643 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola... |
| CVE-2025-52642 | MEDIUM | 6.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ... |
| CVE-2025-52636 | HIGH | 7.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of... |
| CVE-2025-2274 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store... |
| CVE-2025-71264 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash). |
| CVE-2025-6969 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-69246 | CRITICAL | 9.8 | 0.4% | Mar 16, 2026 | Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa... |
| CVE-2025-69245 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici... |
| CVE-2025-69243 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta... |
| CVE-2025-69242 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ... |
| CVE-2025-69241 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic... |
| CVE-2025-69240 | HIGH | 8.8 | 0.1% | Mar 16, 2026 | Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ... |
| CVE-2025-69239 | LOW | 2.7 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker... |
| CVE-2025-69238 | MEDIUM | 4.3 | 0.1% | Mar 16, 2026 | Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh... |
| CVE-2025-69237 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now