2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31200 | CRITICAL | 9.8 | 21.3% | Apr 16, 2025 | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4... |
| CVE-2025-2291 | CRITICAL | 9.8 | 0.3% | Apr 16, 2025 | Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, ... |
| CVE-2025-27540 | CRITICAL | 9.8 | 0.8% | Apr 16, 2025 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v... |
| CVE-2025-27539 | CRITICAL | 9.8 | 0.8% | Apr 16, 2025 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v... |
| CVE-2025-27495 | CRITICAL | 9.8 | 0.8% | Apr 16, 2025 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v... |
| CVE-2025-3694 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0... |
| CVE-2025-22088 | CRITICAL | 9.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_... |
| CVE-2025-3693 | CRITICAL | 9.8 | 4.6% | Apr 16, 2025 | A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cg... |
| CVE-2025-3690 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s... |
| CVE-2025-3689 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil... |
| CVE-2025-39601 | CRITICAL | 9.6 | 0.3% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusio... |
| CVE-2025-39557 | CRITICAL | 9.1 | 0.5% | Apr 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-wo... |
| CVE-2025-1981 | CRITICAL | 9.4 | 0.4% | Apr 16, 2025 | Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices... |
| CVE-2025-1980 | CRITICAL | 9.4 | 0.8% | Apr 16, 2025 | The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If ... |
| CVE-2025-3684 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. Th... |
| CVE-2025-3683 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow... |
| CVE-2025-3682 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of... |
| CVE-2025-3681 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f... |
| CVE-2025-3680 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a... |
| CVE-2025-3679 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function ... |
| CVE-2025-3678 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk... |
| CVE-2025-3676 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f... |
| CVE-2025-3495 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker ... |
| CVE-2025-30215 | CRITICAL | 9.6 | 0.5% | Apr 16, 2025 | NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f... |
| CVE-2025-30967 | CRITICAL | 9.6 | 0.2% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now