2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27584 | MEDIUM | 5.4 | 0.2% | Mar 3, 2025 | A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS... |
| CVE-2025-25953 | MEDIUM | 6.5 | 0.4% | Mar 3, 2025 | Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure ... |
| CVE-2025-25952 | MEDIUM | 6.5 | 0.3% | Mar 3, 2025 | An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solution... |
| CVE-2025-25949 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS... |
| CVE-2025-1842 | MEDIUM | 5.3 | 0.4% | Mar 3, 2025 | A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vuln... |
| CVE-2025-27579 | MEDIUM | 5.4 | 0.2% | Mar 3, 2025 | In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka st... |
| CVE-2025-1836 | MEDIUM | 5.3 | 0.3% | Mar 2, 2025 | A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of... |
| CVE-2025-1835 | MEDIUM | 6.3 | 0.3% | Mar 2, 2025 | A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the fu... |
| CVE-2025-1830 | MEDIUM | 4.8 | 0.4% | Mar 2, 2025 | A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown p... |
| CVE-2025-1817 | MEDIUM | 5.4 | 0.3% | Mar 2, 2025 | A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown cod... |
| CVE-2025-1816 | MEDIUM | 5.3 | 0.5% | Mar 2, 2025 | A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This ... |
| CVE-2025-1813 | MEDIUM | 6.5 | 0.3% | Mar 2, 2025 | A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unk... |
| CVE-2025-1810 | MEDIUM | 5.3 | 0.6% | Mar 2, 2025 | A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown functio... |
| CVE-2025-1807 | MEDIUM | 5.1 | 0.3% | Mar 2, 2025 | A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow... |
| CVE-2025-1806 | MEDIUM | 5.3 | 0.3% | Mar 2, 2025 | A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this ... |
| CVE-2025-1799 | MEDIUM | 6.3 | 0.3% | Mar 1, 2025 | A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAc... |
| CVE-2025-1797 | MEDIUM | 6.3 | 0.3% | Mar 1, 2025 | A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun... |
| CVE-2025-1491 | MEDIUM | 6.4 | 0.3% | Mar 1, 2025 | The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play_timeout’ para... |
| CVE-2025-1404 | MEDIUM | 5.3 | 0.4% | Mar 1, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data... |
| CVE-2025-1291 | MEDIUM | 6.4 | 0.3% | Mar 1, 2025 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2025-1730 | MEDIUM | 6.5 | 0.4% | Mar 1, 2025 | The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi... |
| CVE-2025-1502 | MEDIUM | 5.3 | 0.3% | Mar 1, 2025 | The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit... |
| CVE-2025-1459 | MEDIUM | 5.4 | 0.2% | Mar 1, 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(... |
| CVE-2025-0820 | MEDIUM | 6.4 | 0.3% | Mar 1, 2025 | The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all ver... |
| CVE-2025-1780 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now