2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28138 | CRITICAL | 9.8 | 1.0% | Mar 27, 2025 | The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in th... |
| CVE-2025-26909 | CRITICAL | 9.8 | 0.7% | Mar 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-25686 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. |
| CVE-2025-2516 | CRITICAL | 9.5 | 0.1% | Mar 27, 2025 | The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allow... |
| CVE-2025-2857 | CRITICAL | 10 | 1.9% | Mar 27, 2025 | Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in o... |
| CVE-2025-2846 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects t... |
| CVE-2025-2332 | CRITICAL | 9.8 | 0.7% | Mar 27, 2025 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-2831 | CRITICAL | 9.8 | 0.4% | Mar 27, 2025 | A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d46... |
| CVE-2025-26011 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter wi... |
| CVE-2025-26010 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setU... |
| CVE-2025-26008 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter... |
| CVE-2025-26007 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting sys... |
| CVE-2025-26006 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter wi... |
| CVE-2025-26005 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parame... |
| CVE-2025-26004 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi... |
| CVE-2025-26003 | CRITICAL | 9.8 | 0.6% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cg... |
| CVE-2025-26002 | CRITICAL | 9.8 | 0.5% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi p... |
| CVE-2025-25535 | CRITICAL | 9.8 | 0.5% | Mar 26, 2025 | HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted... |
| CVE-2025-30524 | CRITICAL | 9.3 | 0.6% | Mar 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product... |
| CVE-2025-28942 | CRITICAL | 9.3 | 0.6% | Mar 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Tru... |
| CVE-2025-28916 | CRITICAL | 9.8 | 0.8% | Mar 26, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28898 | CRITICAL | 9.3 | 0.6% | Mar 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Mu... |
| CVE-2025-28893 | CRITICAL | 9.9 | 0.7% | Mar 26, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor ... |
| CVE-2025-26941 | CRITICAL | 9.3 | 0.6% | Mar 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church ... |
| CVE-2025-1542 | CRITICAL | 9.3 | 0.4% | Mar 26, 2025 | Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest acc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now