2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43897 | — | — | — | Apr 19, 2025 | Rejected reason: Not used |
| CVE-2025-43896 | — | — | — | Apr 19, 2025 | Rejected reason: Not used |
| CVE-2025-43895 | — | — | — | Apr 19, 2025 | Rejected reason: Not used |
| CVE-2025-43894 | — | — | — | Apr 19, 2025 | Rejected reason: Not used |
| CVE-2025-43893 | — | — | — | Apr 19, 2025 | Rejected reason: Not used |
| CVE-2025-3284 | MEDIUM | 4.3 | 0.1% | Apr 19, 2025 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln... |
| CVE-2025-3278 | CRITICAL | 9.8 | 0.5% | Apr 19, 2025 | The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.... |
| CVE-2025-2010 | HIGH | 7.5 | 1.5% | Apr 19, 2025 | The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2025-43903 | LOW | 3.3 | 0.1% | Apr 18, 2025 | NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting... |
| CVE-2025-3796 | HIGH | 8.8 | 0.4% | Apr 18, 2025 | A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unk... |
| CVE-2025-32953 | HIGH | 8.7 | 0.4% | Apr 18, 2025 | z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubunt... |
| CVE-2025-29058 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component. |
| CVE-2025-3795 | LOW | 3.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun... |
| CVE-2025-36625 | MEDIUM | 4.3 | 0.2% | Apr 18, 2025 | In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http... |
| CVE-2025-32377 | MEDIUM | 6.5 | 0.4% | Apr 18, 2025 | Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models... |
| CVE-2025-28197 | CRITICAL | 9.1 | 0.3% | Apr 18, 2025 | Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py. |
| CVE-2025-25985 | LOW | 2.6 | 0.3% | Apr 18, 2025 | An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim... |
| CVE-2025-25984 | MEDIUM | 6.8 | 0.3% | Apr 18, 2025 | An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim... |
| CVE-2025-25983 | LOW | 3.4 | 0.3% | Apr 18, 2025 | An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64... |
| CVE-2025-28355 | MEDIUM | 4.7 | 0.2% | Apr 18, 2025 | Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execu... |
| CVE-2025-24914 | HIGH | 7.8 | 0.1% | Apr 18, 2025 | When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu... |
| CVE-2025-29513 | MEDIUM | 6.1 | 13.0% | Apr 18, 2025 | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in ... |
| CVE-2025-29512 | MEDIUM | 6.1 | 0.2% | Apr 18, 2025 | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and... |
| CVE-2025-28242 | CRITICAL | 9.8 | 1.7% | Apr 18, 2025 | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session ... |
| CVE-2025-28238 | CRITICAL | 9.8 | 0.3% | Apr 18, 2025 | Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now