2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46274 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en... |
| CVE-2025-46273 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges... |
| CVE-2025-46272 | CRITICAL | 9.3 | 1.3% | Apr 24, 2025 | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke... |
| CVE-2025-46271 | CRITICAL | 9.3 | 2.0% | Apr 24, 2025 | UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu... |
| CVE-2025-26382 | CRITICAL | 9.3 | 0.5% | Apr 24, 2025 | Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue |
| CVE-2025-43859 | CRITICAL | 9.1 | 0.5% | Apr 24, 2025 | h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ... |
| CVE-2025-43858 | CRITICAL | 9.2 | 0.2% | Apr 24, 2025 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.... |
| CVE-2025-31324 | CRITICAL | 9.8 | 99.5% | Apr 24, 2025 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated a... |
| CVE-2025-46264 | CRITICAL | 9.9 | 0.3% | Apr 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload ... |
| CVE-2025-46248 | CRITICAL | 9.3 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar F... |
| CVE-2025-3604 | CRITICAL | 9.8 | 0.6% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3603 | CRITICAL | 9.8 | 0.5% | Apr 24, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-3065 | CRITICAL | 9.1 | 0.9% | Apr 24, 2025 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct... |
| CVE-2025-2767 | CRITICAL | 9.6 | 0.5% | Apr 23, 2025 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-45429 | CRITICAL | 9.8 | 0.9% | Apr 23, 2025 | In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWp... |
| CVE-2025-32969 | CRITICAL | 9.8 | 79.5% | Apr 23, 2025 | XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possib... |
| CVE-2025-32966 | CRITICAL | 9.8 | 3.9% | Apr 23, 2025 | DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE... |
| CVE-2025-45428 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ... |
| CVE-2025-45427 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ... |
| CVE-2025-42605 | CRITICAL | 9.3 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ... |
| CVE-2025-37087 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access... |
| CVE-2025-32965 | CRITICAL | 9.3 | 0.8% | Apr 22, 2025 | xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4... |
| CVE-2025-43951 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the... |
| CVE-2025-43949 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to... |
| CVE-2025-43946 | CRITICAL | 9.8 | 0.8% | Apr 22, 2025 | TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal). |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now