2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32660 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shel... |
| CVE-2025-32658 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects He... |
| CVE-2025-32652 | CRITICAL | 9.9 | 0.3% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicio... |
| CVE-2025-32648 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.Thi... |
| CVE-2025-32636 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local... |
| CVE-2025-32626 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Man... |
| CVE-2025-32583 | CRITICAL | 9.9 | 12.2% | Apr 17, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code... |
| CVE-2025-32572 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue ... |
| CVE-2025-31380 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-li... |
| CVE-2025-29043 | CRITICAL | 9.8 | 1.5% | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234 |
| CVE-2025-29042 | CRITICAL | 9.8 | 1.5% | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the fu... |
| CVE-2025-27302 | CRITICAL | 9.3 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Mar... |
| CVE-2025-27287 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS ... |
| CVE-2025-27286 | CRITICAL | 9.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injecti... |
| CVE-2025-27282 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator ... |
| CVE-2025-24577 | CRITICAL | 9.8 | 0.3% | Apr 17, 2025 | Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-22655 | CRITICAL | 9.3 | 0.4% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD –... |
| CVE-2025-3651 | CRITICAL | 9.3 | 0.2% | Apr 17, 2025 | Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allo... |
| CVE-2025-29047 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra... |
| CVE-2025-29046 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra... |
| CVE-2025-29045 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_te... |
| CVE-2025-29044 | CRITICAL | 9.8 | 0.9% | Apr 17, 2025 | Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via th... |
| CVE-2025-29041 | CRITICAL | 9.8 | 1.1% | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t... |
| CVE-2025-29040 | CRITICAL | 9.8 | 1.1% | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t... |
| CVE-2025-2188 | CRITICAL | 9.1 | 0.3% | Apr 17, 2025 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now