2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27690 | CRITICAL | 9.8 | 0.4% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent... |
| CVE-2025-3115 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing th... |
| CVE-2025-3114 | CRITICAL | 9.4 | 0.5% | Apr 9, 2025 | Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute wit... |
| CVE-2025-32695 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege E... |
| CVE-2025-32642 | CRITICAL | 10 | 0.3% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issu... |
| CVE-2025-32641 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor all... |
| CVE-2025-32576 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web She... |
| CVE-2025-32496 | CRITICAL | 9.6 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web... |
| CVE-2025-31033 | CRITICAL | 9.8 | 0.3% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site ... |
| CVE-2025-31002 | CRITICAL | 9.1 | 0.5% | Apr 9, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Maliciou... |
| CVE-2025-32375 | CRITICAL | 9.8 | 43.8% | Apr 9, 2025 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2025-27797 | CRITICAL | 9.8 | 0.9% | Apr 9, 2025 | OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a... |
| CVE-2025-32461 | CRITICAL | 9.9 | 0.8% | Apr 9, 2025 | wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The... |
| CVE-2025-32460 | CRITICAL | 9.1 | 0.3% | Apr 9, 2025 | GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportVie... |
| CVE-2025-30282 | CRITICAL | 9.1 | 1.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that c... |
| CVE-2025-30281 | CRITICAL | 9.1 | 13.9% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-24447 | CRITICAL | 9.1 | 1.7% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-24446 | CRITICAL | 9.1 | 1.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-22871 | CRITICAL | 9.1 | 0.7% | Apr 8, 2025 | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit... |
| CVE-2025-25226 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database packag... |
| CVE-2025-32028 | CRITICAL | 9.9 | 1.6% | Apr 8, 2025 | HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX... |
| CVE-2025-32020 | CRITICAL | 9.3 | 0.3% | Apr 8, 2025 | The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper... |
| CVE-2025-22466 | CRITICAL | 9.6 | 1.0% | Apr 8, 2025 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica... |
| CVE-2025-31330 | CRITICAL | 9.9 | 0.7% | Apr 8, 2025 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo... |
| CVE-2025-30016 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now