2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1949 | MEDIUM | 6.1 | 0.5% | Mar 4, 2025 | A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown proc... |
| CVE-2025-27402 | MEDIUM | 4.6 | 0.2% | Mar 4, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF ... |
| CVE-2025-27401 | MEDIUM | 4.6 | 0.3% | Mar 4, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of... |
| CVE-2025-27156 | MEDIUM | 5.4 | 0.2% | Mar 4, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing featu... |
| CVE-2025-27155 | MEDIUM | 6.1 | 0.2% | Mar 4, 2025 | Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The ... |
| CVE-2025-27150 | MEDIUM | 6.5 | 0.3% | Mar 4, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect... |
| CVE-2025-26182 | MEDIUM | 6.5 | 0.4% | Mar 4, 2025 | An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageControl... |
| CVE-2025-26091 | MEDIUM | 4.6 | 0.3% | Mar 4, 2025 | A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remot... |
| CVE-2025-26320 | MEDIUM | 6.5 | 0.9% | Mar 4, 2025 | t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address paramet... |
| CVE-2025-1425 | MEDIUM | 4.7 | 0.2% | Mar 4, 2025 | A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file... |
| CVE-2025-27426 | MEDIUM | 5.4 | 0.2% | Mar 4, 2025 | Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. Thi... |
| CVE-2025-27425 | MEDIUM | 4.3 | 0.2% | Mar 4, 2025 | Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the ... |
| CVE-2025-27424 | MEDIUM | 4.3 | 0.2% | Mar 4, 2025 | Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vul... |
| CVE-2025-1938 | MEDIUM | 6.5 | 0.3% | Mar 4, 2025 | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs... |
| CVE-2025-1935 | MEDIUM | 4.3 | 0.3% | Mar 4, 2025 | A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerabilit... |
| CVE-2025-1934 | MEDIUM | 6.5 | 0.4% | Mar 4, 2025 | It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering ga... |
| CVE-2025-22226 | MEDIUM | 6 | 1.7% | Mar 4, 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGF... |
| CVE-2025-0958 | MEDIUM | 6.3 | 0.3% | Mar 4, 2025 | The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all ... |
| CVE-2025-0370 | MEDIUM | 5.4 | 30.5% | Mar 4, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-26849 | MEDIUM | 4.3 | 0.2% | Mar 4, 2025 | There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be use... |
| CVE-2025-0512 | MEDIUM | 5.4 | 0.3% | Mar 4, 2025 | The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-0433 | MEDIUM | 5.4 | 0.3% | Mar 4, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2025-27521 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vul... |
| CVE-2025-0359 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Appli... |
| CVE-2025-1905 | MEDIUM | 6.1 | 0.3% | Mar 4, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now