2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69765 | HIGH | 7.5 | 0.7% | Mar 3, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus... |
| CVE-2025-67840 | HIGH | 7.2 | 3.7% | Mar 3, 2026 | Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil... |
| CVE-2025-63912 | HIGH | 7.5 | 0.1% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da... |
| CVE-2025-63911 | HIGH | 7.2 | 2.3% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti... |
| CVE-2025-63910 | HIGH | 7.2 | 0.4% | Mar 3, 2026 | An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al... |
| CVE-2025-63909 | HIGH | 7.8 | 0.3% | Mar 3, 2026 | Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.... |
| CVE-2025-15599 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers... |
| CVE-2025-62817 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ... |
| CVE-2025-62816 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4... |
| CVE-2025-66680 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele... |
| CVE-2025-66363 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit... |
| CVE-2025-62815 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ... |
| CVE-2025-62814 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ... |
| CVE-2025-70821 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component |
| CVE-2025-64736 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma... |
| CVE-2025-57622 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ... |
| CVE-2025-52365 | HIGH | 7.8 | 0.5% | Mar 3, 2026 | A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ... |
| CVE-2025-59060 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions ... |
| CVE-2025-59059 | CRITICAL | 9.8 | 1.2% | Mar 3, 2026 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ... |
| CVE-2025-15598 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend... |
| CVE-2025-15595 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. |
| CVE-2025-12345 | HIGH | 8.8 | 0.7% | Mar 3, 2026 | A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the functio... |
| CVE-2025-47147 | MEDIUM | 5.7 | 0.1% | Mar 3, 2026 | Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow ... |
| CVE-2025-48654 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. ... |
| CVE-2025-48653 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now