2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26853 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. |
| CVE-2025-26852 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection. |
| CVE-2025-29980 | CRITICAL | 9.8 | 0.5% | Mar 20, 2025 | A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote un... |
| CVE-2025-29922 | CRITICAL | 9.6 | 0.3% | Mar 20, 2025 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t... |
| CVE-2025-29411 | CRITICAL | 9.8 | 0.6% | Mar 20, 2025 | An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows at... |
| CVE-2025-2311 | CRITICAL | 9 | 0.2% | Mar 20, 2025 | Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials ... |
| CVE-2025-2505 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 ... |
| CVE-2025-27786 | CRITICAL | 9.1 | 0.5% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. ... |
| CVE-2025-27783 | CRITICAL | 9.8 | 1.0% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. T... |
| CVE-2025-27782 | CRITICAL | 9.8 | 1.3% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.p... |
| CVE-2025-27781 | CRITICAL | 9.8 | 0.8% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference... |
| CVE-2025-27780 | CRITICAL | 9.8 | 0.8% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_inf... |
| CVE-2025-27779 | CRITICAL | 9.8 | 0.8% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_bl... |
| CVE-2025-27778 | CRITICAL | 9.8 | 0.9% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py... |
| CVE-2025-29926 | CRITICAL | 9.8 | 0.5% | Mar 19, 2025 | XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager ... |
| CVE-2025-29783 | CRITICAL | 9 | 0.8% | Mar 19, 2025 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Moo... |
| CVE-2025-29401 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execut... |
| CVE-2025-29137 | CRITICAL | 9.8 | 0.5% | Mar 19, 2025 | Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set f... |
| CVE-2025-2512 | CRITICAL | 9.8 | 0.9% | Mar 19, 2025 | The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing... |
| CVE-2025-30139 | CRITICAL | 9.8 | 0.4% | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts ... |
| CVE-2025-30137 | CRITICAL | 9.8 | 0.4% | Mar 18, 2025 | An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The ... |
| CVE-2025-24799 | CRITICAL | 9.8 | 86.2% | Mar 18, 2025 | GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the... |
| CVE-2025-21619 | CRITICAL | 9.8 | 0.4% | Mar 18, 2025 | GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the ru... |
| CVE-2025-25595 | CRITICAL | 9.8 | 0.5% | Mar 18, 2025 | A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a bru... |
| CVE-2025-30132 | CRITICAL | 9.1 | 0.3% | Mar 18, 2025 | An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, cr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now