2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29625 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Servic... |
| CVE-2025-29209 | CRITICAL | 9.8 | 0.9% | Apr 18, 2025 | TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub... |
| CVE-2025-28232 | CRITICAL | 9.1 | 0.5% | Apr 18, 2025 | Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad... |
| CVE-2025-28230 | CRITICAL | 9.1 | 0.4% | Apr 18, 2025 | Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent... |
| CVE-2025-28229 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic... |
| CVE-2025-28228 | HIGH | 7.5 | 1.6% | Apr 18, 2025 | A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and... |
| CVE-2025-40364 | HIGH | 7.8 | 0.3% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffe... |
| CVE-2025-3790 | MEDIUM | 6.9 | 0.6% | Apr 18, 2025 | A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /dr... |
| CVE-2025-3789 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown... |
| CVE-2025-32790 | MEDIUM | 4.3 | 0.2% | Apr 18, 2025 | Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the ... |
| CVE-2025-3788 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is a... |
| CVE-2025-3787 | MEDIUM | 6.5 | 0.4% | Apr 18, 2025 | A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of t... |
| CVE-2025-3106 | MEDIUM | 6.4 | 0.3% | Apr 18, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-3786 | HIGH | 8.8 | 0.9% | Apr 18, 2025 | A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fr... |
| CVE-2025-3785 | HIGH | 8.8 | 8.6% | Apr 18, 2025 | A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown ... |
| CVE-2025-3056 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2025-2492 | CRITICAL | 9.2 | 1.0% | Apr 18, 2025 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req... |
| CVE-2025-40325 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard re... |
| CVE-2025-40114 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_... |
| CVE-2025-40014 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access i... |
| CVE-2025-39989 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-... |
| CVE-2025-39930 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_no... |
| CVE-2025-39778 | HIGH | 7.1 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in n... |
| CVE-2025-39755 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_... |
| CVE-2025-39735 | HIGH | 7.1 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() Durin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now