2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46646MEDIUM4.5In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issu...
CVE-2025-2101HIGH8.1The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via th...
CVE-2025-2851HIGH8.6A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shad...
CVE-2025-2850MEDIUM5.1A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750...
CVE-2025-2811MEDIUM6.9A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750...
CVE-2025-3915MEDIUM4.3The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili...
CVE-2025-3914HIGH8.8The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2025-3906HIGH8.8The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-3491HIGH7.2The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i...
CVE-2025-2907CRITICAL9.8The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settin...
CVE-2025-2105HIGH8.1The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8....
CVE-2025-1458MEDIUM5.4The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is v...
CVE-2025-2801HIGH7.3The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerab...
CVE-2025-46333HIGH7.3z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from ...
CVE-2025-32986HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
CVE-2025-32985CRITICAL9.8NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
CVE-2025-32984MEDIUM6.1NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
CVE-2025-32983HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
CVE-2025-32982HIGH7.5NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
CVE-2025-32981HIGH7.1NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
CVE-2025-32980CRITICAL9.8NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.
CVE-2025-32979MEDIUM6.5NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
CVE-2025-28128HIGH7An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a craft...
CVE-2025-3935HIGH7.2ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web ...
CVE-2025-25775CRITICAL9.8Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tik...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now