2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29780 | MEDIUM | 5.8 | 0.2% | Mar 14, 2025 | Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret ... |
| CVE-2025-29779 | MEDIUM | 5.4 | 0.2% | Mar 14, 2025 | Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret ... |
| CVE-2025-26312 | MEDIUM | 5.3 | 0.3% | Mar 14, 2025 | SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter. |
| CVE-2025-27606 | MEDIUM | 4.6 | 0.2% | Mar 14, 2025 | Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain... |
| CVE-2025-1888 | MEDIUM | 4.6 | 0.2% | Mar 14, 2025 | The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS).... |
| CVE-2025-25873 | MEDIUM | 5.5 | 0.2% | Mar 14, 2025 | Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges... |
| CVE-2025-25872 | MEDIUM | 5.5 | 0.3% | Mar 14, 2025 | An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function |
| CVE-2025-29032 | MEDIUM | 5.9 | 3.8% | Mar 14, 2025 | Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function. |
| CVE-2025-26626 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software p... |
| CVE-2025-1507 | MEDIUM | 5.3 | 0.3% | Mar 14, 2025 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-1526 | MEDIUM | 5.4 | 0.2% | Mar 14, 2025 | The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Displa... |
| CVE-2025-2166 | MEDIUM | 6.1 | 0.3% | Mar 14, 2025 | The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cro... |
| CVE-2025-1528 | MEDIUM | 4.3 | 0.2% | Mar 14, 2025 | The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
| CVE-2025-1285 | MEDIUM | 5.3 | 0.3% | Mar 14, 2025 | The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capab... |
| CVE-2025-0955 | MEDIUM | 5.3 | 0.3% | Mar 14, 2025 | The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th... |
| CVE-2025-30022 | MEDIUM | 6.8 | 0.3% | Mar 14, 2025 | CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter. |
| CVE-2025-25363 | MEDIUM | 6.5 | 0.2% | Mar 13, 2025 | An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira D... |
| CVE-2025-29768 | MEDIUM | 4.4 | 0.3% | Mar 13, 2025 | Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to... |
| CVE-2025-28011 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management... |
| CVE-2025-27103 | MEDIUM | 6.5 | 0.4% | Mar 13, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the ... |
| CVE-2025-24974 | MEDIUM | 6.5 | 0.4% | Mar 13, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated use... |
| CVE-2025-1767 | MEDIUM | 6.5 | 0.5% | Mar 13, 2025 | This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other p... |
| CVE-2025-28015 | MEDIUM | 5.3 | 0.3% | Mar 13, 2025 | A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and... |
| CVE-2025-28010 | MEDIUM | 5.4 | 0.2% | Mar 13, 2025 | A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenti... |
| CVE-2025-25625 | MEDIUM | 5.4 | 0.2% | Mar 13, 2025 | A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fs... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now