2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5124 | CRITICAL | 9.2 | 0.9% | May 24, 2025 | A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N a... |
| CVE-2025-5058 | CRITICAL | 9.8 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-4603 | CRITICAL | 9.1 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi... |
| CVE-2025-4336 | CRITICAL | 9.8 | 1.1% | May 24, 2025 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2025-48756 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small... |
| CVE-2025-48755 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type). |
| CVE-2025-48753 | CRITICAL | 9.8 | 0.2% | May 24, 2025 | In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. |
| CVE-2025-48752 | CRITICAL | 9.8 | 0.3% | May 24, 2025 | In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked. |
| CVE-2025-48751 | CRITICAL | 9.8 | 0.2% | May 24, 2025 | The process_lock crate 0.1.0 for Rust allows data races in unlock. |
| CVE-2025-5119 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code o... |
| CVE-2025-5114 | CRITICAL | 9.1 | 0.4% | May 23, 2025 | A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affect... |
| CVE-2025-5112 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o... |
| CVE-2025-5111 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is... |
| CVE-2025-5110 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-5109 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th... |
| CVE-2025-5108 | CRITICAL | 9.8 | 0.3% | May 23, 2025 | A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo... |
| CVE-2025-5107 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown co... |
| CVE-2025-48289 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issu... |
| CVE-2025-48287 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Inject... |
| CVE-2025-48283 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support M... |
| CVE-2025-47687 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
| CVE-2025-47663 | CRITICAL | 9.9 | 0.3% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web... |
| CVE-2025-47646 | CRITICAL | 9.8 | 21.7% | May 23, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Regi... |
| CVE-2025-47642 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em... |
| CVE-2025-47641 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for W... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now