2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31612 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affec... |
| CVE-2025-31579 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EXEIdeas Internati... |
| CVE-2025-31553 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced... |
| CVE-2025-31552 | CRITICAL | 9.3 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMar... |
| CVE-2025-31551 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Sales... |
| CVE-2025-31534 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shop... |
| CVE-2025-31531 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log... |
| CVE-2025-30841 | CRITICAL | 9.9 | 0.7% | Apr 1, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Cl... |
| CVE-2025-30807 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next... |
| CVE-2025-30580 | CRITICAL | 10 | 0.6% | Apr 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidget... |
| CVE-2025-3096 | CRITICAL | 9.3 | 1.3% | Apr 1, 2025 | Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page. |
| CVE-2025-3085 | CRITICAL | 9.8 | 0.3% | Apr 1, 2025 | A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails t... |
| CVE-2025-2237 | CRITICAL | 9.8 | 0.4% | Apr 1, 2025 | The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u... |
| CVE-2025-30065 | CRITICAL | 9.8 | 38.8% | Apr 1, 2025 | Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar... |
| CVE-2025-31095 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard ... |
| CVE-2025-31087 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerc... |
| CVE-2025-31084 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Obje... |
| CVE-2025-30971 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Rand... |
| CVE-2025-30911 | CRITICAL | 9.9 | 1.7% | Apr 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allo... |
| CVE-2025-30886 | CRITICAL | 10 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De... |
| CVE-2025-30878 | CRITICAL | 9.1 | 0.6% | Apr 1, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-... |
| CVE-2025-30876 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads... |
| CVE-2025-30870 | CRITICAL | 9.8 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30849 | CRITICAL | 9.8 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30774 | CRITICAL | 9.8 | 0.3% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now