2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27929 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. |
| CVE-2025-27927 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. |
| CVE-2025-27892 | MEDIUM | 6.8 | 11.3% | Apr 15, 2025 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:... |
| CVE-2025-27719 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | Unauthenticated attackers can query an API endpoint and get device details. |
| CVE-2025-27575 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. |
| CVE-2025-27565 | MEDIUM | 5.3 | 0.2% | Apr 15, 2025 | An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. |
| CVE-2025-27561 | MEDIUM | 6.9 | 0.2% | Apr 15, 2025 | Unauthenticated attackers can rename "rooms" of arbitrary users. |
| CVE-2025-27011 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-27008 | HIGH | 7.5 | 0.4% | Apr 15, 2025 | Missing Authorization vulnerability in NotFound Unlimited Timeline unlimited-timeline allows Accessing Functionality Not... |
| CVE-2025-26998 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B... |
| CVE-2025-26996 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets a... |
| CVE-2025-26953 | HIGH | 7.5 | 0.4% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetMenu jet-menu allows Accessing Functionality Not Properly Constrain... |
| CVE-2025-26951 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Bloc... |
| CVE-2025-26950 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali... |
| CVE-2025-26934 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy... |
| CVE-2025-26930 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home S... |
| CVE-2025-26927 | CRITICAL | 10 | 0.4% | Apr 15, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to ... |
| CVE-2025-26919 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá tai... |
| CVE-2025-26908 | HIGH | 7.6 | 0.4% | Apr 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gurmehub Kargo Ent... |
| CVE-2025-26906 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Del... |
| CVE-2025-26903 | MEDIUM | 4.3 | 0.1% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Fo... |
| CVE-2025-26880 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT S... |
| CVE-2025-26870 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-26857 | MEDIUM | 5.3 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). |
| CVE-2025-26749 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now