2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52648 | CRITICAL | 9.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ... |
| CVE-2025-15060 | CRITICAL | 9.8 | 1.6% | Mar 16, 2026 | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2025-70245 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode. |
| CVE-2025-59388 | CRITICAL | 9.8 | 0.5% | Mar 12, 2026 | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th... |
| CVE-2025-70041 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. |
| CVE-2025-70024 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk... |
| CVE-2025-66956 | CRITICAL | 9.9 | 0.6% | Mar 11, 2026 | Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t... |
| CVE-2025-70082 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio... |
| CVE-2025-67041 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse... |
| CVE-2025-67039 | CRITICAL | 9.1 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe... |
| CVE-2025-67038 | CRITICAL | 9.8 | 1.1% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ... |
| CVE-2025-67035 | CRITICAL | 9.8 | 0.3% | Mar 11, 2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS ... |
| CVE-2025-69615 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n... |
| CVE-2025-69614 | CRITICAL | 9.4 | 0.4% | Mar 10, 2026 | Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets... |
| CVE-2025-56422 | CRITICAL | 9.8 | 0.9% | Mar 10, 2026 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o... |
| CVE-2025-41709 | CRITICAL | 9.8 | 2.2% | Mar 10, 2026 | An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a... |
| CVE-2025-40943 | CRITICAL | 9.6 | 0.5% | Mar 10, 2026 | Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug... |
| CVE-2025-11158 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric... |
| CVE-2025-70039 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag... |
| CVE-2025-70046 | CRITICAL | 9.8 | 0.4% | Mar 9, 2026 | An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro... |
| CVE-2025-70042 | CRITICAL | 9.8 | 0.3% | Mar 9, 2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. |
| CVE-2025-40639 | CRITICAL | 9.8 | 0.3% | Mar 9, 2026 | A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up... |
| CVE-2025-41765 | CRITICAL | 9.1 | 0.3% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to... |
| CVE-2025-41764 | CRITICAL | 9.1 | 0.4% | Mar 9, 2026 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to... |
| CVE-2025-59543 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now