2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39557 | CRITICAL | 9.1 | 0.5% | Apr 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-wo... |
| CVE-2025-1981 | CRITICAL | 9.4 | 0.4% | Apr 16, 2025 | Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices... |
| CVE-2025-1980 | CRITICAL | 9.4 | 0.8% | Apr 16, 2025 | The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If ... |
| CVE-2025-3684 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. Th... |
| CVE-2025-3683 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow... |
| CVE-2025-3682 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of... |
| CVE-2025-3681 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f... |
| CVE-2025-3680 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a... |
| CVE-2025-3679 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function ... |
| CVE-2025-3678 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk... |
| CVE-2025-3676 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f... |
| CVE-2025-3495 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker ... |
| CVE-2025-30215 | CRITICAL | 9.6 | 0.5% | Apr 16, 2025 | NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f... |
| CVE-2025-30967 | CRITICAL | 9.6 | 0.2% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i... |
| CVE-2025-30510 | CRITICAL | 9.8 | 0.2% | Apr 15, 2025 | An attacker can upload an arbitrary file instead of a plant image. |
| CVE-2025-26927 | CRITICAL | 10 | 0.4% | Apr 15, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to ... |
| CVE-2025-24297 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o... |
| CVE-2025-32778 | CRITICAL | 9.3 | 20.0% | Apr 15, 2025 | Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens... |
| CVE-2025-30727 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported version... |
| CVE-2025-32445 | CRITICAL | 9.9 | 0.7% | Apr 15, 2025 | Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify Eve... |
| CVE-2025-30206 | CRITICAL | 9.8 | 0.7% | Apr 15, 2025 | Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service co... |
| CVE-2025-2567 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling... |
| CVE-2025-28399 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of... |
| CVE-2025-25456 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2. |
| CVE-2025-22900 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now