2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27797 | CRITICAL | 9.8 | 0.9% | Apr 9, 2025 | OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a... |
| CVE-2025-32461 | CRITICAL | 9.9 | 0.8% | Apr 9, 2025 | wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The... |
| CVE-2025-32460 | CRITICAL | 9.1 | 0.3% | Apr 9, 2025 | GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportVie... |
| CVE-2025-30282 | CRITICAL | 9.1 | 1.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that c... |
| CVE-2025-30281 | CRITICAL | 9.1 | 13.9% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-24447 | CRITICAL | 9.1 | 1.7% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-24446 | CRITICAL | 9.1 | 1.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-22871 | CRITICAL | 9.1 | 0.7% | Apr 8, 2025 | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit... |
| CVE-2025-25226 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database packag... |
| CVE-2025-32028 | CRITICAL | 9.9 | 1.6% | Apr 8, 2025 | HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX... |
| CVE-2025-32020 | CRITICAL | 9.3 | 0.3% | Apr 8, 2025 | The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper... |
| CVE-2025-22466 | CRITICAL | 9.6 | 1.0% | Apr 8, 2025 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica... |
| CVE-2025-31330 | CRITICAL | 9.9 | 0.7% | Apr 8, 2025 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo... |
| CVE-2025-30016 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vul... |
| CVE-2025-27429 | CRITICAL | 9.9 | 0.7% | Apr 8, 2025 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T... |
| CVE-2025-2004 | CRITICAL | 9.1 | 0.7% | Apr 8, 2025 | The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2025-3401 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability aff... |
| CVE-2025-3400 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unk... |
| CVE-2025-3399 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by th... |
| CVE-2025-3398 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct... |
| CVE-2025-3363 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3362 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3361 | CRITICAL | 9.8 | 1.3% | Apr 8, 2025 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-3384 | CRITICAL | 9.8 | 0.5% | Apr 7, 2025 | A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Aff... |
| CVE-2025-3383 | CRITICAL | 9.8 | 0.5% | Apr 7, 2025 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now