2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32403 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
| CVE-2025-32401 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d... |
| CVE-2025-3844 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to... |
| CVE-2025-0855 | CRITICAL | 9.8 | 0.5% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ... |
| CVE-2025-47419 | CRITICAL | 10 | 0.2% | May 6, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ... |
| CVE-2025-46572 | CRITICAL | 9.3 | 0.4% | May 6, 2025 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ... |
| CVE-2025-44899 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we... |
| CVE-2025-44073 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. |
| CVE-2025-46816 | CRITICAL | 9.4 | 0.6% | May 6, 2025 | goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a... |
| CVE-2025-25014 | CRITICAL | 9.8 | 13.7% | May 6, 2025 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea... |
| CVE-2025-4041 | CRITICAL | 9.3 | 0.6% | May 6, 2025 | In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh serve... |
| CVE-2025-4368 | CRITICAL | 9.8 | 0.7% | May 6, 2025 | A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetR... |
| CVE-2025-4363 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue ... |
| CVE-2025-45492 | CRITICAL | 9.8 | 1.4% | May 6, 2025 | Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function. |
| CVE-2025-45491 | CRITICAL | 9.8 | 2.1% | May 6, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun... |
| CVE-2025-45490 | CRITICAL | 9.8 | 1.7% | May 6, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun... |
| CVE-2025-45489 | CRITICAL | 9.8 | 1.9% | May 6, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun... |
| CVE-2025-45488 | CRITICAL | 9.8 | 8.8% | May 6, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun... |
| CVE-2025-45487 | CRITICAL | 9.8 | 8.8% | May 6, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection fu... |
| CVE-2025-4362 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. This vulnerability affects u... |
| CVE-2025-4361 | CRITICAL | 9.8 | 0.5% | May 6, 2025 | A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. This affects ... |
| CVE-2025-4360 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by... |
| CVE-2025-4359 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerabili... |
| CVE-2025-4358 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is a... |
| CVE-2025-4357 | CRITICAL | 9.8 | 11.7% | May 6, 2025 | A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now