2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23250 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r... |
| CVE-2025-23249 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co... |
| CVE-2025-29547 | HIGH | 7 | 0.3% | Apr 22, 2025 | In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service becaus... |
| CVE-2025-23176 | HIGH | 8.8 | 0.4% | Apr 22, 2025 | CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2025-1951 | MEDIUM | 6.7 | 0.2% | Apr 22, 2025 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman... |
| CVE-2025-1950 | HIGH | 7.8 | 0.2% | Apr 22, 2025 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman... |
| CVE-2025-28034 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-28033 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-28032 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-23175 | MEDIUM | 6.1 | 0.2% | Apr 22, 2025 | Multiple XSS (CWE-79) |
| CVE-2025-3472 | CRITICAL | 9.8 | 1.7% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
| CVE-2025-3458 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter i... |
| CVE-2025-3457 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortc... |
| CVE-2025-2092 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 ... |
| CVE-2025-46254 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi... |
| CVE-2025-46253 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit g... |
| CVE-2025-46252 | HIGH | 7.2 | 0.4% | Apr 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Messag... |
| CVE-2025-46251 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forg... |
| CVE-2025-46250 | MEDIUM | 4.8 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUF... |
| CVE-2025-46249 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor a... |
| CVE-2025-46247 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces... |
| CVE-2025-46246 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Reques... |
| CVE-2025-46245 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site ... |
| CVE-2025-46244 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo... |
| CVE-2025-46243 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abando... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now