2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30168 | MEDIUM | 6.9 | 0.4% | Mar 21, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 a... |
| CVE-2025-2598 | MEDIUM | 5.7 | 0.3% | Mar 21, 2025 | When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which... |
| CVE-2025-2593 | MEDIUM | 6.3 | 0.3% | Mar 21, 2025 | A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an u... |
| CVE-2025-29640 | MEDIUM | 5.4 | 0.2% | Mar 21, 2025 | Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-repo... |
| CVE-2025-27612 | MEDIUM | 5.9 | 0.2% | Mar 21, 2025 | libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the ten... |
| CVE-2025-2591 | MEDIUM | 5.5 | 0.6% | Mar 21, 2025 | A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect... |
| CVE-2025-2590 | MEDIUM | 5.4 | 0.3% | Mar 21, 2025 | A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic... |
| CVE-2025-2597 | MEDIUM | 6.1 | 0.2% | Mar 21, 2025 | Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability co... |
| CVE-2025-2587 | MEDIUM | 6.3 | 0.3% | Mar 21, 2025 | A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the fi... |
| CVE-2025-30179 | MEDIUM | 6.5 | 0.3% | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, whi... |
| CVE-2025-27933 | MEDIUM | 4.3 | 0.2% | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion rest... |
| CVE-2025-24920 | MEDIUM | 4.3 | 0.2% | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark cre... |
| CVE-2025-2584 | MEDIUM | 6.8 | 0.5% | Mar 21, 2025 | A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the f... |
| CVE-2025-30348 | MEDIUM | 5.3 | 0.3% | Mar 21, 2025 | encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts ... |
| CVE-2025-30346 | MEDIUM | 4.8 | 0.3% | Mar 21, 2025 | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. |
| CVE-2025-2583 | MEDIUM | 6.1 | 0.4% | Mar 21, 2025 | A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown pa... |
| CVE-2025-2582 | MEDIUM | 5.4 | 0.4% | Mar 21, 2025 | A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unkn... |
| CVE-2025-30345 | MEDIUM | 4.1 | 0.3% | Mar 21, 2025 | An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i... |
| CVE-2025-30343 | MEDIUM | 6.5 | 0.4% | Mar 21, 2025 | A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and ... |
| CVE-2025-30342 | MEDIUM | 6.1 | 0.2% | Mar 21, 2025 | An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda T... |
| CVE-2025-2557 | MEDIUM | 5.5 | 0.2% | Mar 20, 2025 | A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is som... |
| CVE-2025-29218 | MEDIUM | 6.5 | 0.5% | Mar 20, 2025 | Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. T... |
| CVE-2025-29217 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. ... |
| CVE-2025-2556 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknow... |
| CVE-2025-2553 | MEDIUM | 5.3 | 1.1% | Mar 20, 2025 | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now