2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46646 | MEDIUM | 4.5 | 0.2% | Apr 26, 2025 | In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issu... |
| CVE-2025-2101 | HIGH | 8.1 | 0.7% | Apr 26, 2025 | The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via th... |
| CVE-2025-2851 | HIGH | 8.6 | 0.4% | Apr 26, 2025 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shad... |
| CVE-2025-2850 | MEDIUM | 5.1 | 0.2% | Apr 26, 2025 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750... |
| CVE-2025-2811 | MEDIUM | 6.9 | 0.3% | Apr 26, 2025 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750... |
| CVE-2025-3915 | MEDIUM | 4.3 | 0.3% | Apr 26, 2025 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili... |
| CVE-2025-3914 | HIGH | 8.8 | 11.4% | Apr 26, 2025 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val... |
| CVE-2025-3906 | HIGH | 8.8 | 0.4% | Apr 26, 2025 | The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-3491 | HIGH | 7.2 | 0.6% | Apr 26, 2025 | The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i... |
| CVE-2025-2907 | CRITICAL | 9.8 | 1.3% | Apr 26, 2025 | The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settin... |
| CVE-2025-2105 | HIGH | 8.1 | 0.6% | Apr 26, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.... |
| CVE-2025-1458 | MEDIUM | 5.4 | 0.2% | Apr 26, 2025 | The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is v... |
| CVE-2025-2801 | HIGH | 7.3 | 0.4% | Apr 26, 2025 | The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerab... |
| CVE-2025-46333 | HIGH | 7.3 | 0.1% | Apr 25, 2025 | z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from ... |
| CVE-2025-32986 | HIGH | 7.5 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint. |
| CVE-2025-32985 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. |
| CVE-2025-32984 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter. |
| CVE-2025-32983 | HIGH | 7.5 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace. |
| CVE-2025-32982 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module. |
| CVE-2025-32981 | HIGH | 7.1 | 0.2% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File. |
| CVE-2025-32980 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration. |
| CVE-2025-32979 | MEDIUM | 6.5 | 0.3% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users. |
| CVE-2025-28128 | HIGH | 7 | 0.4% | Apr 25, 2025 | An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a craft... |
| CVE-2025-3935 | HIGH | 7.2 | 3.3% | Apr 25, 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web ... |
| CVE-2025-25775 | CRITICAL | 9.8 | 0.5% | Apr 25, 2025 | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tik... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now