2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44868 | CRITICAL | 9.8 | 2.6% | May 2, 2025 | Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.... |
| CVE-2025-3927 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t... |
| CVE-2025-2421 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Inj... |
| CVE-2025-2812 | CRITICAL | 9.8 | 0.4% | May 2, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics... |
| CVE-2025-3709 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attacker... |
| CVE-2025-3708 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-3746 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions... |
| CVE-2025-4195 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerabilit... |
| CVE-2025-4193 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-4192 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This aff... |
| CVE-2025-4191 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. Affected ... |
| CVE-2025-4184 | CRITICAL | 9.8 | 0.6% | May 2, 2025 | A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t... |
| CVE-2025-4183 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com... |
| CVE-2025-4182 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-4181 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is... |
| CVE-2025-4180 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function... |
| CVE-2025-4176 | CRITICAL | 9.8 | 0.5% | May 1, 2025 | A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as critical. This v... |
| CVE-2025-43595 | CRITICAL | 9.8 | 0.3% | May 1, 2025 | An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute com... |
| CVE-2025-4174 | CRITICAL | 9.8 | 0.5% | May 1, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A... |
| CVE-2025-35996 | CRITICAL | 9 | 11.2% | May 1, 2025 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename... |
| CVE-2025-32011 | CRITICAL | 9.8 | 21.8% | May 1, 2025 | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can byp... |
| CVE-2025-24522 | CRITICAL | 10 | 0.7% | May 1, 2025 | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-... |
| CVE-2025-46566 | CRITICAL | 9.8 | 0.6% | May 1, 2025 | DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE... |
| CVE-2025-46337 | CRITICAL | 10 | 0.6% | May 1, 2025 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to... |
| CVE-2025-4164 | CRITICAL | 9.8 | 0.4% | May 1, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. Affect... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now