2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50201 | CRITICAL | 9.8 | 4.9% | Jun 19, 2025 | WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id... |
| CVE-2025-52467 | CRITICAL | 9.1 | 0.3% | Jun 19, 2025 | pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c... |
| CVE-2025-24288 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default ... |
| CVE-2025-49591 | CRITICAL | 9.1 | 0.4% | Jun 18, 2025 | CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad... |
| CVE-2025-26199 | CRITICAL | 9.8 | 0.5% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm... |
| CVE-2025-26198 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The... |
| CVE-2025-20260 | CRITICAL | 9.8 | 1.5% | Jun 18, 2025 | A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe... |
| CVE-2025-46157 | CRITICAL | 9.9 | 0.8% | Jun 18, 2025 | An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function... |
| CVE-2025-45784 | CRITICAL | 9.8 | 0.5% | Jun 18, 2025 | D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may... |
| CVE-2025-1562 | CRITICAL | 9.8 | 2.9% | Jun 18, 2025 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word... |
| CVE-2025-51381 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at... |
| CVE-2025-49825 | CRITICAL | 9.8 | 7.8% | Jun 17, 2025 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions... |
| CVE-2025-49217 | CRITICAL | 9.8 | 1.0% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49216 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to ac... |
| CVE-2025-49213 | CRITICAL | 9.8 | 7.9% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49212 | CRITICAL | 9.8 | 7.9% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49220 | CRITICAL | 9.8 | 1.9% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat... |
| CVE-2025-49219 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica... |
| CVE-2025-47867 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta... |
| CVE-2025-47865 | CRITICAL | 9.8 | 1.2% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker... |
| CVE-2025-49452 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Ladó PostaP... |
| CVE-2025-49447 | CRITICAL | 10 | 0.3% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files.... |
| CVE-2025-49444 | CRITICAL | 10 | 0.3% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor all... |
| CVE-2025-49330 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho... |
| CVE-2025-49071 | CRITICAL | 10 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now