2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51381 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at... |
| CVE-2025-49825 | CRITICAL | 9.8 | 7.8% | Jun 17, 2025 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions... |
| CVE-2025-49217 | CRITICAL | 9.8 | 1.0% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49216 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to ac... |
| CVE-2025-49213 | CRITICAL | 9.8 | 7.9% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49212 | CRITICAL | 9.8 | 7.9% | Jun 17, 2025 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica... |
| CVE-2025-49220 | CRITICAL | 9.8 | 1.9% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat... |
| CVE-2025-49219 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica... |
| CVE-2025-47867 | CRITICAL | 9.8 | 1.3% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta... |
| CVE-2025-47865 | CRITICAL | 9.8 | 1.2% | Jun 17, 2025 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker... |
| CVE-2025-49452 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Ladó PostaP... |
| CVE-2025-49447 | CRITICAL | 10 | 0.3% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files.... |
| CVE-2025-49444 | CRITICAL | 10 | 0.3% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor all... |
| CVE-2025-49330 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho... |
| CVE-2025-49071 | CRITICAL | 10 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell... |
| CVE-2025-47573 | CRITICAL | 9.3 | 0.4% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Ma... |
| CVE-2025-47559 | CRITICAL | 9.9 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg allows Upload a Web Shell to a ... |
| CVE-2025-47452 | CRITICAL | 9.9 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web ... |
| CVE-2025-39479 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart ... |
| CVE-2025-32510 | CRITICAL | 10 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager all... |
| CVE-2025-31919 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: fro... |
| CVE-2025-30618 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows ... |
| CVE-2025-24773 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPCRM - C... |
| CVE-2025-4404 | CRITICAL | 9.1 | 1.8% | Jun 17, 2025 | A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to ... |
| CVE-2025-3515 | CRITICAL | 9.8 | 5.1% | Jun 17, 2025 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now