2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27429 | CRITICAL | 9.9 | 0.7% | Apr 8, 2025 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T... |
| CVE-2025-2004 | CRITICAL | 9.1 | 0.7% | Apr 8, 2025 | The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2025-3401 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability aff... |
| CVE-2025-3400 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unk... |
| CVE-2025-3399 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by th... |
| CVE-2025-3398 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct... |
| CVE-2025-3363 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3362 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3361 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3384 | CRITICAL | 9.8 | 0.5% | Apr 7, 2025 | A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Aff... |
| CVE-2025-3383 | CRITICAL | 9.8 | 0.5% | Apr 7, 2025 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical.... |
| CVE-2025-3381 | CRITICAL | 9.8 | 0.9% | Apr 7, 2025 | A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown pa... |
| CVE-2025-3380 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is s... |
| CVE-2025-3379 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown... |
| CVE-2025-3378 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the ... |
| CVE-2025-3377 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown proc... |
| CVE-2025-3376 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow... |
| CVE-2025-3375 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of... |
| CVE-2025-3374 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f... |
| CVE-2025-3373 | CRITICAL | 9.8 | 0.7% | Apr 7, 2025 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a... |
| CVE-2025-28413 | CRITICAL | 9.8 | 0.6% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component |
| CVE-2025-28412 | CRITICAL | 9.8 | 0.6% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeControlle... |
| CVE-2025-28411 | CRITICAL | 9.8 | 0.6% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave |
| CVE-2025-28410 | CRITICAL | 9.8 | 0.6% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not prop... |
| CVE-2025-28408 | CRITICAL | 9.8 | 0.6% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now