2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70616 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the I... |
| CVE-2025-70233 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard. |
| CVE-2025-70232 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter. |
| CVE-2025-70231 | CRITICAL | 9.8 | 0.7% | Mar 5, 2026 | D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verificati... |
| CVE-2025-70230 | CRITICAL | 9.8 | 0.8% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS. |
| CVE-2025-70229 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule. |
| CVE-2025-45691 | HIGH | 7.5 | 0.5% | Mar 5, 2026 | An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.... |
| CVE-2025-13476 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientH... |
| CVE-2025-64166 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability w... |
| CVE-2025-69534 | HIGH | 7.5 | 0.6% | Mar 5, 2026 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser... |
| CVE-2025-11143 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Different... |
| CVE-2025-66319 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerabilit... |
| CVE-2025-69411 | HIGH | 7.5 | 1.6% | Mar 5, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger i... |
| CVE-2025-69343 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Thea... |
| CVE-2025-69340 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad... |
| CVE-2025-69339 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69338 | CRITICAL | 9.3 | 0.4% | Mar 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C... |
| CVE-2025-69090 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68555 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a... |
| CVE-2025-68554 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Fil... |
| CVE-2025-68553 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a... |
| CVE-2025-68515 | MEDIUM | 5.8 | 0.3% | Mar 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allow... |
| CVE-2025-54001 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects... |
| CVE-2025-53335 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-40931 | CRITICAL | 9.1 | 0.6% | Mar 5, 2026 | Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now