2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3800 | CRITICAL | 9.8 | 0.5% | Apr 19, 2025 | A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown funct... |
| CVE-2025-3799 | CRITICAL | 9.8 | 0.4% | Apr 19, 2025 | A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app... |
| CVE-2025-1093 | CRITICAL | 9.8 | 0.9% | Apr 19, 2025 | The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat... |
| CVE-2025-3278 | CRITICAL | 9.8 | 0.5% | Apr 19, 2025 | The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.... |
| CVE-2025-29058 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component. |
| CVE-2025-28197 | CRITICAL | 9.1 | 0.3% | Apr 18, 2025 | Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py. |
| CVE-2025-28242 | CRITICAL | 9.8 | 1.7% | Apr 18, 2025 | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session ... |
| CVE-2025-28238 | CRITICAL | 9.8 | 0.3% | Apr 18, 2025 | Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers t... |
| CVE-2025-28236 | CRITICAL | 9.8 | 0.3% | Apr 18, 2025 | Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerabili... |
| CVE-2025-28233 | CRITICAL | 9.1 | 0.3% | Apr 18, 2025 | Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Ve... |
| CVE-2025-28231 | CRITICAL | 9.1 | 0.4% | Apr 18, 2025 | Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary comma... |
| CVE-2025-32434 | CRITICAL | 9.8 | 1.9% | Apr 18, 2025 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built... |
| CVE-2025-29953 | CRITICAL | 9.8 | 1.6% | Apr 18, 2025 | Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache Activ... |
| CVE-2025-29209 | CRITICAL | 9.8 | 0.9% | Apr 18, 2025 | TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub... |
| CVE-2025-28232 | CRITICAL | 9.1 | 0.5% | Apr 18, 2025 | Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad... |
| CVE-2025-28230 | CRITICAL | 9.1 | 0.4% | Apr 18, 2025 | Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent... |
| CVE-2025-28229 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic... |
| CVE-2025-2492 | CRITICAL | 9.2 | 1.0% | Apr 18, 2025 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req... |
| CVE-2025-3783 | CRITICAL | 9.8 | 0.8% | Apr 18, 2025 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff... |
| CVE-2025-1863 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se... |
| CVE-2025-39471 | CRITICAL | 9.3 | 0.3% | Apr 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S... |
| CVE-2025-42599 | CRITICAL | 9.8 | 3.0% | Apr 18, 2025 | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp... |
| CVE-2025-3762 | CRITICAL | 9.8 | 0.6% | Apr 17, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-28009 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2... |
| CVE-2025-2947 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now