2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22939 | CRITICAL | 9.8 | 2.4% | Mar 31, 2025 | A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate pr... |
| CVE-2025-22938 | CRITICAL | 9.8 | 0.5% | Mar 31, 2025 | Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords. |
| CVE-2025-22937 | CRITICAL | 9.8 | 0.5% | Mar 31, 2025 | An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors. |
| CVE-2025-29266 | CRITICAL | 9.6 | 0.4% | Mar 31, 2025 | Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication... |
| CVE-2025-3022 | CRITICAL | 9.3 | 1.0% | Mar 31, 2025 | Os command injection vulnerability in e-solutions e-management. This vulnerability allows an attacker to execute arbitra... |
| CVE-2025-2071 | CRITICAL | 10 | 0.9% | Mar 31, 2025 | A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote at... |
| CVE-2025-2978 | CRITICAL | 9.8 | 0.5% | Mar 31, 2025 | A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionalit... |
| CVE-2025-26689 | CRITICAL | 9.8 | 1.1% | Mar 31, 2025 | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker... |
| CVE-2025-25211 | CRITICAL | 9.8 | 0.8% | Mar 31, 2025 | Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, ... |
| CVE-2025-3011 | CRITICAL | 9.8 | 0.5% | Mar 31, 2025 | SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary... |
| CVE-2025-2973 | CRITICAL | 9.8 | 0.4% | Mar 31, 2025 | A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affect... |
| CVE-2025-1268 | CRITICAL | 9.4 | 0.8% | Mar 31, 2025 | Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer D... |
| CVE-2025-2952 | CRITICAL | 9.8 | 0.4% | Mar 30, 2025 | A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-2951 | CRITICAL | 9.8 | 0.4% | Mar 30, 2025 | A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the... |
| CVE-2025-1861 | CRITICAL | 9.8 | 0.8% | Mar 30, 2025 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsi... |
| CVE-2025-2266 | CRITICAL | 9.8 | 0.6% | Mar 29, 2025 | The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that ... |
| CVE-2025-28091 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. |
| CVE-2025-28090 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. |
| CVE-2025-28089 | CRITICAL | 9.1 | 0.4% | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. |
| CVE-2025-28087 | CRITICAL | 9.8 | 0.4% | Mar 28, 2025 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. |
| CVE-2025-25579 | CRITICAL | 9.8 | 8.4% | Mar 28, 2025 | TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. |
| CVE-2025-2927 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown func... |
| CVE-2025-28256 | CRITICAL | 9.8 | 0.8% | Mar 28, 2025 | An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWla... |
| CVE-2025-22953 | CRITICAL | 9.8 | 1.4% | Mar 28, 2025 | A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC... |
| CVE-2025-30372 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now