2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29662 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system ... |
| CVE-2025-43012 | CRITICAL | 9.8 | 0.7% | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible |
| CVE-2025-39596 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects ... |
| CVE-2025-39595 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Qu... |
| CVE-2025-39588 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allow... |
| CVE-2025-39587 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calc... |
| CVE-2025-39551 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injectio... |
| CVE-2025-39550 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Inject... |
| CVE-2025-39436 | CRITICAL | 9.1 | 0.6% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This i... |
| CVE-2025-32682 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps al... |
| CVE-2025-32665 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Offi... |
| CVE-2025-32660 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shel... |
| CVE-2025-32658 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects He... |
| CVE-2025-32652 | CRITICAL | 9.9 | 0.3% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicio... |
| CVE-2025-32648 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.Thi... |
| CVE-2025-32636 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local... |
| CVE-2025-32626 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Man... |
| CVE-2025-32583 | CRITICAL | 9.9 | 12.2% | Apr 17, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code... |
| CVE-2025-32572 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue ... |
| CVE-2025-31380 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-li... |
| CVE-2025-29043 | CRITICAL | 9.8 | 1.5% | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234 |
| CVE-2025-29042 | CRITICAL | 9.8 | 1.5% | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the fu... |
| CVE-2025-27302 | CRITICAL | 9.3 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Mar... |
| CVE-2025-27287 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS ... |
| CVE-2025-27286 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injecti... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now