2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2562 | MEDIUM | 5.4 | 0.4% | Mar 26, 2025 | Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated ... |
| CVE-2025-2499 | MEDIUM | 5.4 | 0.4% | Mar 26, 2025 | Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An auth... |
| CVE-2025-30350 | MEDIUM | 5.3 | 0.4% | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` packa... |
| CVE-2025-30225 | MEDIUM | 5.3 | 0.4% | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` packa... |
| CVE-2025-30164 | MEDIUM | 6.1 | 0.2% | Mar 26, 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio... |
| CVE-2025-27609 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio... |
| CVE-2025-27405 | MEDIUM | 6.1 | 0.3% | Mar 26, 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio... |
| CVE-2025-2820 | MEDIUM | 6.5 | 0.5% | Mar 26, 2025 | An authenticated attacker can compromise the availability of the device via the network |
| CVE-2025-2819 | MEDIUM | 6.6 | 0.2% | Mar 26, 2025 | There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validat... |
| CVE-2025-28885 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fiverraffiliates F... |
| CVE-2025-27404 | MEDIUM | 6.1 | 0.6% | Mar 26, 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versio... |
| CVE-2025-26929 | MEDIUM | 5.9 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Account... |
| CVE-2025-26923 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event p... |
| CVE-2025-26922 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techthemes AuraMar... |
| CVE-2025-26869 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Build allows Store... |
| CVE-2025-26747 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes Rain... |
| CVE-2025-26739 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction news... |
| CVE-2025-26559 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor Secur... |
| CVE-2025-26537 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rolomak GDPR Tools... |
| CVE-2025-24972 | MEDIUM | 4.3 | 0.4% | Mar 26, 2025 | Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t... |
| CVE-2025-23203 | MEDIUM | 5.5 | 0.4% | Mar 26, 2025 | Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 a... |
| CVE-2025-2228 | MEDIUM | 5.7 | 0.3% | Mar 26, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2025-1911 | MEDIUM | 6.5 | 0.4% | Mar 26, 2025 | The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitr... |
| CVE-2025-1769 | MEDIUM | 4.9 | 0.8% | Mar 26, 2025 | The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Direct... |
| CVE-2025-1312 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now