2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32569 | CRITICAL | 9.8 | 0.7% | Apr 11, 2025 | Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.Thi... |
| CVE-2025-32568 | CRITICAL | 9.8 | 0.7% | Apr 11, 2025 | Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object ... |
| CVE-2025-32565 | CRITICAL | 9.3 | 0.4% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Produc... |
| CVE-2025-32519 | CRITICAL | 9.8 | 0.7% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32491 | CRITICAL | 9.8 | 0.6% | Apr 11, 2025 | Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analy... |
| CVE-2025-31599 | CRITICAL | 9.3 | 0.5% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Produ... |
| CVE-2025-31565 | CRITICAL | 9.3 | 0.6% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez ... |
| CVE-2025-32743 | CRITICAL | 9 | 0.4% | Apr 10, 2025 | In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca... |
| CVE-2025-32755 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De... |
| CVE-2025-32754 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on... |
| CVE-2025-22375 | CRITICAL | 9.3 | 0.4% | Apr 10, 2025 | An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an... |
| CVE-2025-32206 | CRITICAL | 9.1 | 0.5% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows U... |
| CVE-2025-32202 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articul... |
| CVE-2025-32140 | CRITICAL | 9.9 | 0.4% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnai... |
| CVE-2025-27690 | CRITICAL | 9.8 | 0.4% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent... |
| CVE-2025-3115 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing th... |
| CVE-2025-3114 | CRITICAL | 9.4 | 0.5% | Apr 9, 2025 | Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute wit... |
| CVE-2025-32695 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege E... |
| CVE-2025-32642 | CRITICAL | 10 | 0.3% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issu... |
| CVE-2025-32641 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor all... |
| CVE-2025-32576 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web She... |
| CVE-2025-32496 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web... |
| CVE-2025-31033 | CRITICAL | 9.8 | 0.3% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site ... |
| CVE-2025-31002 | CRITICAL | 9.1 | 0.5% | Apr 9, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Maliciou... |
| CVE-2025-32375 | CRITICAL | 9.8 | 43.8% | Apr 9, 2025 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now