2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4248 | CRITICAL | 9.8 | 0.4% | May 4, 2025 | A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by th... |
| CVE-2025-4242 | CRITICAL | 9.8 | 0.3% | May 3, 2025 | A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vul... |
| CVE-2025-4241 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Af... |
| CVE-2025-4240 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown proc... |
| CVE-2025-4239 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow... |
| CVE-2025-4238 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of... |
| CVE-2025-4237 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f... |
| CVE-2025-4236 | CRITICAL | 9.8 | 0.6% | May 3, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a... |
| CVE-2025-4226 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This aff... |
| CVE-2025-3918 | CRITICAL | 9.8 | 0.5% | May 3, 2025 | The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg... |
| CVE-2025-4214 | CRITICAL | 9.8 | 0.4% | May 2, 2025 | A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue af... |
| CVE-2025-4213 | CRITICAL | 9.8 | 0.3% | May 2, 2025 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulner... |
| CVE-2025-45800 | CRITICAL | 9.8 | 0.7% | May 2, 2025 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the... |
| CVE-2025-44877 | CRITICAL | 9.8 | 2.0% | May 2, 2025 | Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via... |
| CVE-2025-44872 | CRITICAL | 9.8 | 2.0% | May 2, 2025 | Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via... |
| CVE-2025-44868 | CRITICAL | 9.8 | 2.6% | May 2, 2025 | Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.... |
| CVE-2025-3927 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t... |
| CVE-2025-2421 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Inj... |
| CVE-2025-2812 | CRITICAL | 9.8 | 0.4% | May 2, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics... |
| CVE-2025-3709 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attacker... |
| CVE-2025-3708 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-3746 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions... |
| CVE-2025-4195 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerabilit... |
| CVE-2025-4193 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-4192 | CRITICAL | 9.8 | 0.5% | May 2, 2025 | A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This aff... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now