2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30138 | MEDIUM | 4.6 | 0.2% | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging ... |
| CVE-2025-29930 | MEDIUM | 6.9 | 0.4% | Mar 18, 2025 | imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] param... |
| CVE-2025-29790 | MEDIUM | 5.4 | 0.2% | Mar 18, 2025 | Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and... |
| CVE-2025-27080 | MEDIUM | 6 | 0.2% | Mar 18, 2025 | Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive... |
| CVE-2025-25042 | MEDIUM | 4.3 | 0.3% | Mar 18, 2025 | A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view se... |
| CVE-2025-2487 | MEDIUM | 4.9 | 0.6% | Mar 18, 2025 | A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the l... |
| CVE-2025-26138 | MEDIUM | 6.5 | 0.3% | Mar 18, 2025 | Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.asp... |
| CVE-2025-25586 | MEDIUM | 4.2 | 0.1% | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources... |
| CVE-2025-25582 | MEDIUM | 6.1 | 0.2% | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /... |
| CVE-2025-30110 | MEDIUM | 6.5 | 0.3% | Mar 18, 2025 | On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism reli... |
| CVE-2025-30109 | MEDIUM | 6.5 | 0.2% | Mar 18, 2025 | In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for t... |
| CVE-2025-2491 | MEDIUM | 5.4 | 0.3% | Mar 18, 2025 | A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the... |
| CVE-2025-25590 | MEDIUM | 6.1 | 0.2% | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressD... |
| CVE-2025-25580 | MEDIUM | 6.1 | 0.2% | Mar 18, 2025 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml... |
| CVE-2025-2490 | MEDIUM | 5.4 | 0.3% | Mar 18, 2025 | A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the functi... |
| CVE-2025-2495 | MEDIUM | 5.4 | 0.2% | Mar 18, 2025 | Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to uplo... |
| CVE-2025-2489 | MEDIUM | 6.8 | 0.2% | Mar 18, 2025 | Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow a... |
| CVE-2025-0694 | MEDIUM | 6.6 | 0.3% | Mar 18, 2025 | Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesy... |
| CVE-2025-2420 | MEDIUM | 5.3 | 0.2% | Mar 17, 2025 | A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affec... |
| CVE-2025-29781 | MEDIUM | 6.5 | 0.2% | Mar 17, 2025 | The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator en... |
| CVE-2025-2397 | MEDIUM | 4.8 | 0.2% | Mar 17, 2025 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 2... |
| CVE-2025-2393 | MEDIUM | 5.1 | 0.4% | Mar 17, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.... |
| CVE-2025-29426 | MEDIUM | 4.6 | 0.2% | Mar 17, 2025 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.p... |
| CVE-2025-26393 | MEDIUM | 5.4 | 0.3% | Mar 17, 2025 | SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to es... |
| CVE-2025-24185 | MEDIUM | 5.5 | 0.2% | Mar 17, 2025 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now