2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69649 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary wi... |
| CVE-2025-69651 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ... |
| CVE-2025-69646 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_... |
| CVE-2025-69645 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug ... |
| CVE-2025-69644 | MEDIUM | 5 | 0.1% | Mar 6, 2026 | An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing ... |
| CVE-2025-70363 | HIGH | 7.5 | 0.2% | Mar 6, 2026 | Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated ... |
| CVE-2025-15602 | HIGH | 8.8 | 0.5% | Mar 6, 2026 | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently... |
| CVE-2025-59544 | MEDIUM | 4.3 | 0.2% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category... |
| CVE-2025-59543 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
| CVE-2025-59542 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
| CVE-2025-59541 | HIGH | 8.1 | 0.2% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability all... |
| CVE-2025-59540 | MEDIUM | 5.4 | 0.2% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that... |
| CVE-2025-55289 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V... |
| CVE-2025-30413 | MEDIUM | 4.4 | 0.2% | Mar 6, 2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber... |
| CVE-2025-11792 | HIGH | 7.3 | 0.1% | Mar 6, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-11791 | HIGH | 7.1 | 0.1% | Mar 6, 2026 | Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a... |
| CVE-2025-11790 | MEDIUM | 4.4 | 0.1% | Mar 6, 2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber... |
| CVE-2025-70995 | HIGH | 8.8 | 0.6% | Mar 5, 2026 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code executi... |
| CVE-2025-70949 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a t... |
| CVE-2025-70948 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ... |
| CVE-2025-70614 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web... |
| CVE-2025-55208 | CRITICAL | 9 | 0.3% | Mar 5, 2026 | Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S... |
| CVE-2025-29165 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component |
| CVE-2025-13350 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: D... |
| CVE-2025-7375 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now