2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30035 | CRITICAL | 9 | 0.2% | Mar 2, 2026 | The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ... |
| CVE-2025-10350 | HIGH | 8.8 | 0.2% | Mar 2, 2026 | SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attack... |
| CVE-2025-15597 | MEDIUM | 6.3 | 0.5% | Mar 2, 2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps... |
| CVE-2025-13673 | HIGH | 7.5 | 0.5% | Feb 28, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon... |
| CVE-2025-69437 | HIGH | 8.7 | 0.3% | Feb 27, 2026 | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ... |
| CVE-2025-15498 | CRITICAL | 9.3 | 0.5% | Feb 27, 2026 | Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ... |
| CVE-2025-10990 | HIGH | 7.5 | 0.5% | Feb 27, 2026 | A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin... |
| CVE-2025-11950 | MEDIUM | 6.1 | 0.2% | Feb 27, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Adva... |
| CVE-2025-11252 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ... |
| CVE-2025-11251 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I... |
| CVE-2025-14142 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t... |
| CVE-2025-12150 | LOW | 3.1 | 0.2% | Feb 27, 2026 | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf... |
| CVE-2025-9909 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows ... |
| CVE-2025-9908 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerabilit... |
| CVE-2025-9907 | MEDIUM | 6.7 | 0.2% | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerabi... |
| CVE-2025-9572 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi... |
| CVE-2025-13327 | MEDIUM | 6.3 | 0.1% | Feb 27, 2026 | A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or ins... |
| CVE-2025-15567 | LOW | 3.3 | 0.1% | Feb 27, 2026 | Insufficient protection mechanisms in the Health Module may lead to partial information disclosure. |
| CVE-2025-15509 | MEDIUM | 4.3 | 0.3% | Feb 27, 2026 | The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2025-14149 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-14040 | MEDIUM | 6.4 | 0.3% | Feb 27, 2026 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-12981 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i... |
| CVE-2025-40932 | HIGH | 8.2 | 0.2% | Feb 27, 2026 | Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse... |
| CVE-2025-11384 | — | — | — | Feb 26, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-11383 | — | — | — | Feb 26, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now