2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28100 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co... |
| CVE-2025-32911 | CRITICAL | 9 | 0.8% | Apr 15, 2025 | A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function... |
| CVE-2025-28137 | CRITICAL | 9.8 | 10.3% | Apr 15, 2025 | The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th... |
| CVE-2025-30985 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe... |
| CVE-2025-3579 | CRITICAL | 9.3 | 0.5% | Apr 15, 2025 | In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute una... |
| CVE-2025-3578 | CRITICAL | 9.3 | 0.4% | Apr 15, 2025 | A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify... |
| CVE-2025-32428 | CRITICAL | 9 | 0.8% | Apr 15, 2025 | Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant t... |
| CVE-2025-24797 | CRITICAL | 9.8 | 0.7% | Apr 15, 2025 | Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protob... |
| CVE-2025-3593 | CRITICAL | 9.8 | 0.4% | Apr 14, 2025 | A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerab... |
| CVE-2025-3589 | CRITICAL | 9.8 | 0.4% | Apr 14, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affect... |
| CVE-2025-1782 | CRITICAL | 9.9 | 0.5% | Apr 14, 2025 | In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used... |
| CVE-2025-3277 | CRITICAL | 9.8 | 0.6% | Apr 14, 2025 | An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used t... |
| CVE-2025-32931 | CRITICAL | 9.1 | 0.5% | Apr 14, 2025 | DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb... |
| CVE-2025-22372 | CRITICAL | 9.3 | 0.2% | Apr 14, 2025 | Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are ei... |
| CVE-2025-22371 | CRITICAL | 9.3 | 0.5% | Apr 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (S... |
| CVE-2025-3559 | CRITICAL | 9.8 | 0.4% | Apr 14, 2025 | A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the... |
| CVE-2025-3558 | CRITICAL | 9.8 | 0.4% | Apr 14, 2025 | A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown par... |
| CVE-2025-3553 | CRITICAL | 9.8 | 0.4% | Apr 14, 2025 | A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_de... |
| CVE-2025-0129 | CRITICAL | 9.3 | 0.2% | Apr 11, 2025 | An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma A... |
| CVE-2025-3439 | CRITICAL | 9.8 | 1.1% | Apr 11, 2025 | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ... |
| CVE-2025-23391 | CRITICAL | 9.1 | 0.4% | Apr 11, 2025 | A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password ... |
| CVE-2025-32607 | CRITICAL | 9.8 | 0.7% | Apr 11, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Inje... |
| CVE-2025-32603 | CRITICAL | 9.3 | 0.4% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users... |
| CVE-2025-32579 | CRITICAL | 9.9 | 0.6% | Apr 11, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload ... |
| CVE-2025-32577 | CRITICAL | 9.8 | 0.7% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now