2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46828 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve... |
| CVE-2025-20221 | CRITICAL | 9.1 | 0.4% | May 7, 2025 | A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote ... |
| CVE-2025-20188 | CRITICAL | 10 | 17.9% | May 7, 2025 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de... |
| CVE-2025-47688 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec... |
| CVE-2025-47657 | CRITICAL | 9.3 | 0.3% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds P... |
| CVE-2025-47635 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Req... |
| CVE-2025-47548 | CRITICAL | 9.8 | 0.2% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress act... |
| CVE-2025-2777 | CRITICAL | 9.8 | 79.1% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the l... |
| CVE-2025-2776 | CRITICAL | 9.8 | 73.0% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S... |
| CVE-2025-4104 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t... |
| CVE-2025-20968 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20967 | CRITICAL | 9.1 | 0.2% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20949 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary ... |
| CVE-2025-0668 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-32404 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
| CVE-2025-32403 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
| CVE-2025-32401 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d... |
| CVE-2025-3844 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to... |
| CVE-2025-0855 | CRITICAL | 9.8 | 0.5% | May 6, 2025 | The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ... |
| CVE-2025-47419 | CRITICAL | 10 | 0.2% | May 6, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ... |
| CVE-2025-46572 | CRITICAL | 9.3 | 0.4% | May 6, 2025 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ... |
| CVE-2025-44899 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we... |
| CVE-2025-44073 | CRITICAL | 9.8 | 0.4% | May 6, 2025 | SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. |
| CVE-2025-46816 | CRITICAL | 9.4 | 0.6% | May 6, 2025 | goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a... |
| CVE-2025-25014 | CRITICAL | 9.8 | 13.7% | May 6, 2025 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now