2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1726 | MEDIUM | 4.3 | 0.4% | Feb 26, 2025 | There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a ... |
| CVE-2025-20161 | MEDIUM | 5.1 | 0.5% | Feb 26, 2025 | A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches... |
| CVE-2025-20119 | MEDIUM | 5.7 | 0.1% | Feb 26, 2025 | A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to ove... |
| CVE-2025-20118 | MEDIUM | 4.4 | 0.1% | Feb 26, 2025 | A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local... |
| CVE-2025-20117 | MEDIUM | 6.7 | 0.2% | Feb 26, 2025 | A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as r... |
| CVE-2025-20116 | MEDIUM | 4.8 | 0.3% | Feb 26, 2025 | A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack... |
| CVE-2025-0941 | MEDIUM | 5.8 | 0.2% | Feb 26, 2025 | MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain te... |
| CVE-2025-25462 | MEDIUM | 5.5 | 0.3% | Feb 26, 2025 | A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v... |
| CVE-2025-25827 | MEDIUM | 6.8 | 0.2% | Feb 26, 2025 | A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and in... |
| CVE-2025-25818 | MEDIUM | 5.1 | 0.2% | Feb 26, 2025 | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2025-25813 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php. |
| CVE-2025-25802 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php. |
| CVE-2025-25800 | MEDIUM | 5.3 | 0.5% | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa... |
| CVE-2025-25799 | MEDIUM | 6 | 0.2% | Feb 26, 2025 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa... |
| CVE-2025-25797 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php. |
| CVE-2025-25796 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php. |
| CVE-2025-25794 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php. |
| CVE-2025-25793 | MEDIUM | 5.1 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php. |
| CVE-2025-25792 | MEDIUM | 4.4 | 0.7% | Feb 26, 2025 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_wei... |
| CVE-2025-25791 | MEDIUM | 4.4 | 0.3% | Feb 26, 2025 | An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute a... |
| CVE-2025-1249 | MEDIUM | 5.3 | 0.3% | Feb 26, 2025 | Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly ... |
| CVE-2025-26925 | MEDIUM | 4.3 | 0.2% | Feb 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This is... |
| CVE-2025-0719 | MEDIUM | 6.1 | 0.3% | Feb 26, 2025 | IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an... |
| CVE-2025-1517 | MEDIUM | 5.4 | 0.5% | Feb 26, 2025 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2025-0731 | MEDIUM | 6.5 | 0.7% | Feb 26, 2025 | An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now