2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3085 | CRITICAL | 9.8 | 0.3% | Apr 1, 2025 | A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails t... |
| CVE-2025-2237 | CRITICAL | 9.8 | 0.4% | Apr 1, 2025 | The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u... |
| CVE-2025-30065 | CRITICAL | 9.8 | 38.8% | Apr 1, 2025 | Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar... |
| CVE-2025-31095 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard ... |
| CVE-2025-31087 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerc... |
| CVE-2025-31084 | CRITICAL | 9.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Obje... |
| CVE-2025-30971 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Rand... |
| CVE-2025-30911 | CRITICAL | 9.9 | 1.7% | Apr 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allo... |
| CVE-2025-30886 | CRITICAL | 10 | 0.5% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De... |
| CVE-2025-30878 | CRITICAL | 9.1 | 0.6% | Apr 1, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-... |
| CVE-2025-30876 | CRITICAL | 9.3 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads... |
| CVE-2025-30870 | CRITICAL | 9.8 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30849 | CRITICAL | 9.8 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30774 | CRITICAL | 9.8 | 0.3% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker... |
| CVE-2025-30622 | CRITICAL | 9.3 | 0.3% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash... |
| CVE-2025-3045 | CRITICAL | 9.8 | 0.5% | Apr 1, 2025 | A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management Sy... |
| CVE-2025-3042 | CRITICAL | 9.8 | 0.4% | Apr 1, 2025 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability a... |
| CVE-2025-3041 | CRITICAL | 9.8 | 0.4% | Apr 1, 2025 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an... |
| CVE-2025-3040 | CRITICAL | 9.8 | 0.5% | Mar 31, 2025 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by ... |
| CVE-2025-31194 | CRITICAL | 9.8 | 0.9% | Mar 31, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S... |
| CVE-2025-31183 | CRITICAL | 9.8 | 1.1% | Mar 31, 2025 | The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 1... |
| CVE-2025-31182 | CRITICAL | 9.8 | 1.1% | Mar 31, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequ... |
| CVE-2025-30465 | CRITICAL | 9.8 | 0.9% | Mar 31, 2025 | A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, ma... |
| CVE-2025-30462 | CRITICAL | 9.8 | 0.8% | Mar 31, 2025 | A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS S... |
| CVE-2025-30461 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in mac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now