2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1390 | MEDIUM | 6.1 | 0.1% | Feb 18, 2025 | The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configu... |
| CVE-2025-25223 | MEDIUM | 5.3 | 0.6% | Feb 18, 2025 | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal v... |
| CVE-2025-25055 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to ... |
| CVE-2025-1392 | MEDIUM | 5.4 | 6.8% | Feb 17, 2025 | A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is... |
| CVE-2025-1391 | MEDIUM | 5.4 | 0.4% | Feb 17, 2025 | A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a use... |
| CVE-2025-26778 | MEDIUM | 5.9 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery... |
| CVE-2025-26775 | MEDIUM | 4.8 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR wo... |
| CVE-2025-26772 | MEDIUM | 5.4 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit... |
| CVE-2025-26771 | MEDIUM | 5.4 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B... |
| CVE-2025-26770 | MEDIUM | 6.5 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Waymark waymar... |
| CVE-2025-26769 | MEDIUM | 6.5 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilia Inc. Verte... |
| CVE-2025-26758 | MEDIUM | 5.3 | 0.4% | Feb 17, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social M... |
| CVE-2025-26754 | MEDIUM | 6.5 | 0.2% | Feb 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Timeline ... |
| CVE-2025-0714 | MEDIUM | 6.5 | 0.2% | Feb 17, 2025 | The vulnerability exists in the password storage of Mobateks MobaXterm in versions below 25.0. MobaXTerm uses an initial... |
| CVE-2025-0001 | MEDIUM | 6.5 | 0.4% | Feb 17, 2025 | Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitr... |
| CVE-2025-1378 | MEDIUM | 4.8 | 0.3% | Feb 17, 2025 | A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function ... |
| CVE-2025-1377 | MEDIUM | 5.5 | 0.3% | Feb 17, 2025 | A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the funct... |
| CVE-2025-1376 | MEDIUM | 4.7 | 0.3% | Feb 17, 2025 | A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_s... |
| CVE-2025-0924 | MEDIUM | 6.1 | 1.3% | Feb 17, 2025 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all... |
| CVE-2025-1373 | MEDIUM | 5.5 | 0.3% | Feb 17, 2025 | A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function ... |
| CVE-2025-26700 | MEDIUM | 5.2 | 0.2% | Feb 17, 2025 | Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android ver... |
| CVE-2025-1371 | MEDIUM | 5.5 | 0.2% | Feb 17, 2025 | A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the funct... |
| CVE-2025-1370 | MEDIUM | 5.3 | 2.4% | Feb 17, 2025 | A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affecte... |
| CVE-2025-1369 | MEDIUM | 4.5 | 3.3% | Feb 17, 2025 | A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerab... |
| CVE-2025-1368 | MEDIUM | 4.6 | 0.4% | Feb 17, 2025 | A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulner... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now