2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28136 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi. |
| CVE-2025-3608 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea... |
| CVE-2025-32946 | MEDIUM | 5.3 | 0.3% | Apr 15, 2025 | This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. Th... |
| CVE-2025-32945 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. Th... |
| CVE-2025-32944 | MEDIUM | 6.5 | 0.5% | Apr 15, 2025 | The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.... |
| CVE-2025-32103 | MEDIUM | 5 | 12.2% | Apr 15, 2025 | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ ... |
| CVE-2025-32102 | MEDIUM | 5 | 5.7% | Apr 15, 2025 | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=t... |
| CVE-2025-32929 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-bar... |
| CVE-2025-31011 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers S... |
| CVE-2025-30985 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe... |
| CVE-2025-30965 | MEDIUM | 4.3 | 0.1% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue aff... |
| CVE-2025-30964 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forger... |
| CVE-2025-30962 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster ... |
| CVE-2025-26992 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing... |
| CVE-2025-26990 | MEDIUM | 4.9 | 0.2% | Apr 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server... |
| CVE-2025-26982 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächle... |
| CVE-2025-26959 | HIGH | 8.8 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue ... |
| CVE-2025-26958 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrain... |
| CVE-2025-26955 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured... |
| CVE-2025-26954 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooE... |
| CVE-2025-26944 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetPopup jet-popup allows Accessing Functionality Not Properly Constra... |
| CVE-2025-26942 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Const... |
| CVE-2025-26894 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26889 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26745 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Element... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now