2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22526 | CRITICAL | 9.8 | 0.5% | Mar 28, 2025 | Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performanc... |
| CVE-2025-22523 | CRITICAL | 9.3 | 0.3% | Mar 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule... |
| CVE-2025-2859 | CRITICAL | 9.8 | 0.4% | Mar 28, 2025 | An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the activ... |
| CVE-2025-28219 | CRITICAL | 9.8 | 9.7% | Mar 28, 2025 | Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to ... |
| CVE-2025-2294 | CRITICAL | 9.8 | 77.3% | Mar 28, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin... |
| CVE-2025-24383 | CRITICAL | 9.1 | 1.2% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-22398 | CRITICAL | 9.8 | 2.1% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-26898 | CRITICAL | 9.3 | 0.3% | Mar 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-26873 | CRITICAL | 9 | 0.4% | Mar 27, 2025 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a th... |
| CVE-2025-29306 | CRITICAL | 9.8 | 43.7% | Mar 27, 2025 | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm... |
| CVE-2025-30367 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30365 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30364 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.... |
| CVE-2025-30361 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, ... |
| CVE-2025-28138 | CRITICAL | 9.8 | 1.0% | Mar 27, 2025 | The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in th... |
| CVE-2025-26909 | CRITICAL | 9.8 | 0.7% | Mar 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-25686 | CRITICAL | 9.8 | 0.5% | Mar 27, 2025 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. |
| CVE-2025-2516 | CRITICAL | 9.5 | 0.1% | Mar 27, 2025 | The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allow... |
| CVE-2025-2857 | CRITICAL | 10 | 1.9% | Mar 27, 2025 | Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in o... |
| CVE-2025-2846 | CRITICAL | 9.8 | 0.6% | Mar 27, 2025 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects t... |
| CVE-2025-2332 | CRITICAL | 9.8 | 0.7% | Mar 27, 2025 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-2831 | CRITICAL | 9.8 | 0.4% | Mar 27, 2025 | A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d46... |
| CVE-2025-26011 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter wi... |
| CVE-2025-26010 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setU... |
| CVE-2025-26008 | CRITICAL | 9.8 | 0.4% | Mar 26, 2025 | In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now