2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28039 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28038 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28036 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se... |
| CVE-2025-28035 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set... |
| CVE-2025-34028 | CRITICAL | 10 | 97.2% | Apr 22, 2025 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta... |
| CVE-2025-28037 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman... |
| CVE-2025-28024 | CRITICAL | 9.8 | 0.5% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi |
| CVE-2025-23251 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem... |
| CVE-2025-23250 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r... |
| CVE-2025-23249 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co... |
| CVE-2025-28034 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-3472 | CRITICAL | 9.8 | 1.7% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
| CVE-2025-46247 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces... |
| CVE-2025-46244 | CRITICAL | 9.8 | 0.3% | Apr 22, 2025 | Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo... |
| CVE-2025-3856 | CRITICAL | 9.8 | 0.4% | Apr 22, 2025 | A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea... |
| CVE-2025-3847 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part ... |
| CVE-2025-3846 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is ... |
| CVE-2025-3845 | CRITICAL | 9.8 | 0.6% | Apr 21, 2025 | A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner... |
| CVE-2025-3842 | CRITICAL | 9.8 | 0.5% | Apr 21, 2025 | A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse... |
| CVE-2025-32958 | CRITICAL | 9.8 | 0.5% | Apr 21, 2025 | Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses act... |
| CVE-2025-3841 | CRITICAL | 9.8 | 0.4% | Apr 21, 2025 | A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9... |
| CVE-2025-28104 | CRITICAL | 9.1 | 0.3% | Apr 21, 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. |
| CVE-2025-32431 | CRITICAL | 9.1 | 0.8% | Apr 21, 2025 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-... |
| CVE-2025-29660 | CRITICAL | 9.8 | 1.2% | Apr 21, 2025 | A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789.... |
| CVE-2025-29659 | CRITICAL | 9.8 | 1.3% | Apr 21, 2025 | Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now