2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32969 | CRITICAL | 9.8 | 79.5% | Apr 23, 2025 | XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possib... |
| CVE-2025-32966 | CRITICAL | 9.8 | 3.9% | Apr 23, 2025 | DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE... |
| CVE-2025-45428 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ... |
| CVE-2025-45427 | CRITICAL | 9.8 | 0.7% | Apr 23, 2025 | In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ... |
| CVE-2025-42605 | CRITICAL | 9.3 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ... |
| CVE-2025-37087 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access... |
| CVE-2025-32965 | CRITICAL | 9.3 | 0.8% | Apr 22, 2025 | xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4... |
| CVE-2025-43951 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the... |
| CVE-2025-43949 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to... |
| CVE-2025-43946 | CRITICAL | 9.8 | 0.8% | Apr 22, 2025 | TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal). |
| CVE-2025-28039 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28038 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28036 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se... |
| CVE-2025-28035 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set... |
| CVE-2025-34028 | CRITICAL | 10 | 97.2% | Apr 22, 2025 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta... |
| CVE-2025-28037 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman... |
| CVE-2025-28024 | CRITICAL | 9.8 | 0.5% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi |
| CVE-2025-23251 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem... |
| CVE-2025-23250 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r... |
| CVE-2025-23249 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co... |
| CVE-2025-28034 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-3472 | CRITICAL | 9.8 | 1.7% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
| CVE-2025-46247 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces... |
| CVE-2025-46244 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo... |
| CVE-2025-3856 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now