2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2278 | MEDIUM | 6.5 | 0.4% | Mar 13, 2025 | Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and... |
| CVE-2025-1636 | MEDIUM | 6.5 | 1.6% | Mar 13, 2025 | Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Ma... |
| CVE-2025-1635 | MEDIUM | 6.5 | 1.6% | Mar 13, 2025 | Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and ... |
| CVE-2025-21104 | MEDIUM | 6.5 | 0.3% | Mar 13, 2025 | Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redi... |
| CVE-2025-0652 | MEDIUM | 6.5 | 0.4% | Mar 13, 2025 | An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions start... |
| CVE-2025-2104 | MEDIUM | 4.3 | 0.3% | Mar 13, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publ... |
| CVE-2025-1561 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' ... |
| CVE-2025-1503 | MEDIUM | 6.4 | 0.2% | Mar 13, 2025 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field ... |
| CVE-2025-2250 | MEDIUM | 4.9 | 0.4% | Mar 13, 2025 | The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable t... |
| CVE-2025-1559 | MEDIUM | 6.4 | 0.3% | Mar 13, 2025 | The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode ... |
| CVE-2025-22870 | MEDIUM | 4.4 | 0.4% | Mar 12, 2025 | Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when... |
| CVE-2025-0116 | MEDIUM | 6.8 | 0.2% | Mar 12, 2025 | A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot... |
| CVE-2025-0115 | MEDIUM | 6.8 | 0.2% | Mar 12, 2025 | A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbit... |
| CVE-2025-27017 | MEDIUM | 6.5 | 1.1% | Mar 12, 2025 | Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi proven... |
| CVE-2025-25774 | MEDIUM | 6.5 | 0.4% | Mar 12, 2025 | An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specifi... |
| CVE-2025-25683 | MEDIUM | 5.6 | 0.2% | Mar 12, 2025 | AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects Ale... |
| CVE-2025-2002 | MEDIUM | 6 | 0.2% | Mar 12, 2025 | CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP s... |
| CVE-2025-27867 | MEDIUM | 5.6 | 0.5% | Mar 12, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP ... |
| CVE-2025-25566 | MEDIUM | 5.6 | 0.3% | Mar 12, 2025 | Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAl... |
| CVE-2025-20177 | MEDIUM | 6.7 | 0.1% | Mar 12, 2025 | A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisc... |
| CVE-2025-20145 | MEDIUM | 5.8 | 0.4% | Mar 12, 2025 | A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow... |
| CVE-2025-20144 | MEDIUM | 5.8 | 0.3% | Mar 12, 2025 | A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow ... |
| CVE-2025-20143 | MEDIUM | 6.7 | 0.1% | Mar 12, 2025 | A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv... |
| CVE-2025-1984 | MEDIUM | 5.2 | 0.1% | Mar 12, 2025 | Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low... |
| CVE-2025-29891 | MEDIUM | 4.8 | 72.0% | Mar 12, 2025 | Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now