2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27282 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator ... |
| CVE-2025-24577 | CRITICAL | 9.8 | 0.3% | Apr 17, 2025 | Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-22655 | CRITICAL | 9.3 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD –... |
| CVE-2025-3651 | CRITICAL | 9.3 | 0.2% | Apr 17, 2025 | Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allo... |
| CVE-2025-29047 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra... |
| CVE-2025-29046 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra... |
| CVE-2025-29045 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_te... |
| CVE-2025-29044 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via th... |
| CVE-2025-29041 | CRITICAL | 9.8 | 1.1% | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t... |
| CVE-2025-29040 | CRITICAL | 9.8 | 1.1% | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t... |
| CVE-2025-2188 | CRITICAL | 9.1 | 0.3% | Apr 17, 2025 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co... |
| CVE-2025-1532 | CRITICAL | 9.1 | 0.3% | Apr 17, 2025 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affec... |
| CVE-2025-3113 | CRITICAL | 9 | 0.3% | Apr 17, 2025 | A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database con... |
| CVE-2025-31340 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Informa... |
| CVE-2025-0756 | CRITICAL | 9.1 | 0.8% | Apr 16, 2025 | Overview The product receives input from an upstream component, but it does not restrict or incorrectly restric... |
| CVE-2025-32433 | CRITICAL | 10 | 97.7% | Apr 16, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O... |
| CVE-2025-3729 | CRITICAL | 9.8 | 3.0% | Apr 16, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen... |
| CVE-2025-3727 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com... |
| CVE-2025-29709 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfo... |
| CVE-2025-29708 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Se... |
| CVE-2025-3726 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2025-3725 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is... |
| CVE-2025-3724 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function... |
| CVE-2025-3723 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processi... |
| CVE-2025-31201 | CRITICAL | 9.8 | 12.4% | Apr 16, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Seq... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now