2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31927 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:... |
| CVE-2025-31918 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro... |
| CVE-2025-31916 | CRITICAL | 9 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium ... |
| CVE-2025-31914 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel... |
| CVE-2025-31631 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue... |
| CVE-2025-31430 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The... |
| CVE-2025-31423 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec... |
| CVE-2025-31397 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke... |
| CVE-2025-31069 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti... |
| CVE-2025-31056 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar... |
| CVE-2025-31049 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ... |
| CVE-2025-3895 | CRITICAL | 9.1 | 0.4% | May 23, 2025 | Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ... |
| CVE-2025-5099 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c... |
| CVE-2025-5098 | CRITICAL | 9.1 | 0.3% | May 23, 2025 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's... |
| CVE-2025-48373 | CRITICAL | 9.1 | 0.3% | May 22, 2025 | Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ... |
| CVE-2025-30171 | CRITICAL | 9 | 0.3% | May 22, 2025 | System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator ... |
| CVE-2025-2410 | CRITICAL | 9.1 | 0.4% | May 22, 2025 | Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session... |
| CVE-2025-2409 | CRITICAL | 9.1 | 0.4% | May 22, 2025 | File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c... |
| CVE-2025-43596 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands ... |
| CVE-2025-5081 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerab... |
| CVE-2025-5079 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown f... |
| CVE-2025-32814 | CRITICAL | 9.8 | 35.8% | May 22, 2025 | An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. |
| CVE-2025-5078 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the ... |
| CVE-2025-5077 | CRITICAL | 9.8 | 0.4% | May 22, 2025 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an u... |
| CVE-2025-5076 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now