2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32434 | CRITICAL | 9.8 | 1.9% | Apr 18, 2025 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built... |
| CVE-2025-29953 | CRITICAL | 9.8 | 1.6% | Apr 18, 2025 | Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache Activ... |
| CVE-2025-29209 | CRITICAL | 9.8 | 0.9% | Apr 18, 2025 | TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub... |
| CVE-2025-28232 | CRITICAL | 9.1 | 0.5% | Apr 18, 2025 | Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad... |
| CVE-2025-28230 | CRITICAL | 9.1 | 0.4% | Apr 18, 2025 | Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent... |
| CVE-2025-28229 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic... |
| CVE-2025-2492 | CRITICAL | 9.2 | 1.0% | Apr 18, 2025 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req... |
| CVE-2025-3783 | CRITICAL | 9.8 | 0.8% | Apr 18, 2025 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff... |
| CVE-2025-1863 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se... |
| CVE-2025-39471 | CRITICAL | 9.3 | 0.3% | Apr 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S... |
| CVE-2025-42599 | CRITICAL | 9.8 | 3.3% | Apr 18, 2025 | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp... |
| CVE-2025-3762 | CRITICAL | 9.8 | 0.6% | Apr 17, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-28009 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2... |
| CVE-2025-2947 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicio... |
| CVE-2025-29662 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system ... |
| CVE-2025-43012 | CRITICAL | 9.8 | 0.7% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible |
| CVE-2025-39596 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects ... |
| CVE-2025-39595 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Qu... |
| CVE-2025-39588 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allow... |
| CVE-2025-39587 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calc... |
| CVE-2025-39551 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injectio... |
| CVE-2025-39550 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Inject... |
| CVE-2025-39436 | CRITICAL | 9.1 | 0.6% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This i... |
| CVE-2025-32682 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps al... |
| CVE-2025-32665 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Offi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now