2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39377 | HIGH | 8.5 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Hel... |
| CVE-2025-39360 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39359 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32921 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-44135 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_upda... |
| CVE-2025-44134 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/cla... |
| CVE-2025-29568 | MEDIUM | 4.8 | 0.2% | Apr 24, 2025 | A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects ... |
| CVE-2025-43855 | HIGH | 8.7 | 0.3% | Apr 24, 2025 | tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 1... |
| CVE-2025-30409 | MEDIUM | 5.5 | 0.2% | Apr 24, 2025 | Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Prot... |
| CVE-2025-30408 | MEDIUM | 6.7 | 0.1% | Apr 24, 2025 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-46421 | MEDIUM | 6.8 | 0.5% | Apr 24, 2025 | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio... |
| CVE-2025-46420 | MEDIUM | 6.5 | 0.5% | Apr 24, 2025 | A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars... |
| CVE-2025-27820 | HIGH | 7.5 | 0.7% | Apr 24, 2025 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na... |
| CVE-2025-3872 | HIGH | 7.2 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-... |
| CVE-2025-3832 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al... |
| CVE-2025-3793 | MEDIUM | 4.2 | 0.2% | Apr 24, 2025 | The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu... |
| CVE-2025-3776 | HIGH | 8.3 | 0.7% | Apr 24, 2025 | The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions ... |
| CVE-2025-3607 | HIGH | 8.8 | 0.4% | Apr 24, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2025-3604 | CRITICAL | 9.8 | 0.6% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3603 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3300 | HIGH | 7.2 | 0.9% | Apr 24, 2025 | The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all version... |
| CVE-2025-3280 | MEDIUM | 6.5 | 0.3% | Apr 24, 2025 | The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio... |
| CVE-2025-3101 | HIGH | 8.8 | 0.3% | Apr 24, 2025 | The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2025-3065 | CRITICAL | 9.1 | 0.9% | Apr 24, 2025 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct... |
| CVE-2025-3058 | HIGH | 8.8 | 0.4% | Apr 24, 2025 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now