2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23118 | MEDIUM | 6.4 | 0.2% | Mar 1, 2025 | An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Prote... |
| CVE-2025-23117 | MEDIUM | 6.8 | 0.2% | Mar 1, 2025 | An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to Uni... |
| CVE-2025-27416 | MEDIUM | 5.9 | 0.4% | Mar 1, 2025 | Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with ... |
| CVE-2025-25478 | MEDIUM | 6.5 | 0.4% | Feb 28, 2025 | The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mi... |
| CVE-2025-25476 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to e... |
| CVE-2025-26466 | MEDIUM | 5.9 | 38.5% | Feb 28, 2025 | A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a m... |
| CVE-2025-27414 | MEDIUM | 4.6 | 0.5% | Feb 28, 2025 | MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09... |
| CVE-2025-27413 | MEDIUM | 4.9 | 1.1% | Feb 28, 2025 | PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an a... |
| CVE-2025-27410 | MEDIUM | 6.5 | 1.8% | Feb 28, 2025 | PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerab... |
| CVE-2025-0769 | MEDIUM | 6.3 | 0.4% | Feb 28, 2025 | PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is us... |
| CVE-2025-25429 | MEDIUM | 4.8 | 0.3% | Feb 28, 2025 | Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside t... |
| CVE-2025-27408 | MEDIUM | 4.8 | 0.1% | Feb 28, 2025 | Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implem... |
| CVE-2025-25431 | MEDIUM | 4.8 | 0.3% | Feb 28, 2025 | Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_dat... |
| CVE-2025-25430 | MEDIUM | 4.8 | 0.3% | Feb 28, 2025 | Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on ... |
| CVE-2025-24843 | MEDIUM | 5.1 | 0.1% | Feb 28, 2025 | Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confide... |
| CVE-2025-24318 | MEDIUM | 6.8 | 0.3% | Feb 28, 2025 | Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromi... |
| CVE-2025-24316 | MEDIUM | 6.9 | 0.3% | Feb 28, 2025 | The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, ... |
| CVE-2025-23405 | MEDIUM | 6.9 | 0.3% | Feb 28, 2025 | Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attack... |
| CVE-2025-0985 | MEDIUM | 5.5 | 0.2% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that cou... |
| CVE-2025-26263 | MEDIUM | 5.1 | 1.3% | Feb 28, 2025 | GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred... |
| CVE-2025-26047 | MEDIUM | 5.1 | 0.2% | Feb 28, 2025 | Loggrove v1.0 is vulnerable to SQL Injection in the read.py file. |
| CVE-2025-25461 | MEDIUM | 5.4 | 0.5% | Feb 28, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category... |
| CVE-2025-25916 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php. |
| CVE-2025-1776 | MEDIUM | 6.1 | 0.3% | Feb 28, 2025 | Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to exe... |
| CVE-2025-1749 | MEDIUM | 4.7 | 0.2% | Feb 28, 2025 | HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now