2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46673 | CRITICAL | 9.9 | 0.4% | Apr 27, 2025 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a b... |
| CVE-2025-2907 | CRITICAL | 9.8 | 1.3% | Apr 26, 2025 | The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settin... |
| CVE-2025-32985 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. |
| CVE-2025-32980 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration. |
| CVE-2025-25775 | CRITICAL | 9.8 | 0.5% | Apr 25, 2025 | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tik... |
| CVE-2025-46433 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible |
| CVE-2025-32432 | CRITICAL | 10 | 99.8% | Apr 25, 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from vers... |
| CVE-2025-2470 | CRITICAL | 9.8 | 0.4% | Apr 25, 2025 | The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, ... |
| CVE-2025-46616 | CRITICAL | 9.9 | 0.6% | Apr 25, 2025 | Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. T... |
| CVE-2025-46275 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator accou... |
| CVE-2025-46274 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en... |
| CVE-2025-46273 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges... |
| CVE-2025-46272 | CRITICAL | 9.3 | 1.3% | Apr 24, 2025 | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke... |
| CVE-2025-46271 | CRITICAL | 9.3 | 2.0% | Apr 24, 2025 | UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu... |
| CVE-2025-26382 | CRITICAL | 9.3 | 0.5% | Apr 24, 2025 | Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue |
| CVE-2025-43859 | CRITICAL | 9.1 | 0.5% | Apr 24, 2025 | h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ... |
| CVE-2025-43858 | CRITICAL | 9.2 | 0.2% | Apr 24, 2025 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.... |
| CVE-2025-31324 | CRITICAL | 9.8 | 99.5% | Apr 24, 2025 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated a... |
| CVE-2025-46264 | CRITICAL | 9.9 | 0.3% | Apr 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload ... |
| CVE-2025-46248 | CRITICAL | 9.3 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar F... |
| CVE-2025-3604 | CRITICAL | 9.8 | 0.6% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3603 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3065 | CRITICAL | 9.1 | 0.9% | Apr 24, 2025 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct... |
| CVE-2025-2767 | CRITICAL | 9.6 | 0.5% | Apr 23, 2025 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-45429 | CRITICAL | 9.8 | 0.9% | Apr 23, 2025 | In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now