2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25939 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey pa... |
| CVE-2025-27371 | MEDIUM | 6.9 | 0.3% | Mar 3, 2025 | In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication me... |
| CVE-2025-27370 | MEDIUM | 6.9 | 0.3% | Mar 3, 2025 | OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt a... |
| CVE-2025-0686 | MEDIUM | 6.4 | 0.3% | Mar 3, 2025 | A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses... |
| CVE-2025-0685 | MEDIUM | 6.4 | 0.3% | Mar 3, 2025 | A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled pa... |
| CVE-2025-0684 | MEDIUM | 6.4 | 0.3% | Mar 3, 2025 | A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses u... |
| CVE-2025-27498 | MEDIUM | 5.6 | 0.1% | Mar 3, 2025 | aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is t... |
| CVE-2025-25303 | MEDIUM | 6.9 | 0.5% | Mar 3, 2025 | The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTransl... |
| CVE-2025-25302 | MEDIUM | 6.5 | 0.2% | Mar 3, 2025 | Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All ... |
| CVE-2025-0287 | MEDIUM | 5.1 | 0.3% | Mar 3, 2025 | Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by... |
| CVE-2025-27420 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri... |
| CVE-2025-27418 | MEDIUM | 5.4 | 0.2% | Mar 3, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri... |
| CVE-2025-27417 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri... |
| CVE-2025-27099 | MEDIUM | 4.8 | 0.3% | Mar 3, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-sit... |
| CVE-2025-27094 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user w... |
| CVE-2025-24023 | MEDIUM | 5.3 | 0.3% | Mar 3, 2025 | Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users ... |
| CVE-2025-0555 | MEDIUM | 6.1 | 0.4% | Mar 3, 2025 | A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to ... |
| CVE-2025-27274 | MEDIUM | 4.9 | 0.5% | Mar 3, 2025 | Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects G... |
| CVE-2025-27273 | MEDIUM | 5.8 | 0.2% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate ... |
| CVE-2025-26994 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaf... |
| CVE-2025-26989 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaf... |
| CVE-2025-26984 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-26918 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ... |
| CVE-2025-26917 | MEDIUM | 6.1 | 0.3% | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templ... |
| CVE-2025-25137 | MEDIUM | 6.5 | 0.1% | Mar 3, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forg... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now