2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3137 | CRITICAL | 9.8 | 0.5% | Apr 3, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Aff... |
| CVE-2025-3135 | CRITICAL | 9.8 | 0.4% | Apr 3, 2025 | A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerabili... |
| CVE-2025-3120 | CRITICAL | 9.8 | 0.5% | Apr 2, 2025 | A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. Thi... |
| CVE-2025-3119 | CRITICAL | 9.8 | 0.5% | Apr 2, 2025 | A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerabilit... |
| CVE-2025-31484 | CRITICAL | 9.3 | 0.4% | Apr 2, 2025 | conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Be... |
| CVE-2025-31477 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality t... |
| CVE-2025-3118 | CRITICAL | 9.8 | 0.5% | Apr 2, 2025 | A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an... |
| CVE-2025-29085 | CRITICAL | 9.8 | 29.1% | Apr 2, 2025 | SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via ... |
| CVE-2025-29063 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter pass... |
| CVE-2025-29062 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in ... |
| CVE-2025-31286 | CRITICAL | 9 | 0.4% | Apr 2, 2025 | An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute... |
| CVE-2025-2005 | CRITICAL | 9.8 | 17.7% | Apr 2, 2025 | The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-0415 | CRITICAL | 9.2 | 0.5% | Apr 2, 2025 | A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system c... |
| CVE-2025-30356 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2025-31612 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affec... |
| CVE-2025-31579 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EXEIdeas Internati... |
| CVE-2025-31553 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced... |
| CVE-2025-31552 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMar... |
| CVE-2025-31551 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Sales... |
| CVE-2025-31534 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shop... |
| CVE-2025-31531 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log... |
| CVE-2025-30841 | CRITICAL | 9.9 | 0.7% | Apr 1, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Cl... |
| CVE-2025-30807 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next... |
| CVE-2025-30580 | CRITICAL | 10 | 0.6% | Apr 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidget... |
| CVE-2025-3096 | CRITICAL | 9.3 | 1.3% | Apr 1, 2025 | Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now