2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1861 | CRITICAL | 9.8 | 0.8% | Mar 30, 2025 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsi... |
| CVE-2025-2266 | CRITICAL | 9.8 | 0.6% | Mar 29, 2025 | The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that ... |
| CVE-2025-28091 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. |
| CVE-2025-28090 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. |
| CVE-2025-28089 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. |
| CVE-2025-28087 | CRITICAL | 9.8 | 0.4% | Mar 28, 2025 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. |
| CVE-2025-25579 | CRITICAL | 9.8 | 8.4% | Mar 28, 2025 | TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. |
| CVE-2025-2927 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown func... |
| CVE-2025-28256 | CRITICAL | 9.8 | 0.8% | Mar 28, 2025 | An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWla... |
| CVE-2025-22953 | CRITICAL | 9.8 | 1.4% | Mar 28, 2025 | A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC... |
| CVE-2025-30372 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vul... |
| CVE-2025-22526 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performanc... |
| CVE-2025-22523 | CRITICAL | 9.3 | 0.3% | Mar 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule... |
| CVE-2025-2859 | CRITICAL | 9.8 | 0.4% | Mar 28, 2025 | An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the activ... |
| CVE-2025-28219 | CRITICAL | 9.8 | 9.7% | Mar 28, 2025 | Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to ... |
| CVE-2025-2294 | CRITICAL | 9.8 | 77.3% | Mar 28, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin... |
| CVE-2025-24383 | CRITICAL | 9.1 | 1.2% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-22398 | CRITICAL | 9.8 | 2.1% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-26898 | CRITICAL | 9.3 | 0.3% | Mar 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-26873 | CRITICAL | 9 | 0.4% | Mar 27, 2025 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a th... |
| CVE-2025-29306 | CRITICAL | 9.8 | 43.7% | Mar 27, 2025 | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm... |
| CVE-2025-30367 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30365 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30364 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30361 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now