2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1550 | CRITICAL | 9.8 | 2.8% | Mar 11, 2025 | The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually const... |
| CVE-2025-1661 | CRITICAL | 9.8 | 52.8% | Mar 11, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2025-27925 | CRITICAL | 9.8 | 0.4% | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. |
| CVE-2025-25306 | CRITICAL | 9.3 | 0.2% | Mar 10, 2025 | Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate t... |
| CVE-2025-24813 | CRITICAL | 9.8 | 99.9% | Mar 10, 2025 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malic... |
| CVE-2025-25977 | CRITICAL | 9.8 | 0.6% | Mar 10, 2025 | An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement. |
| CVE-2025-25940 | CRITICAL | 9.8 | 0.7% | Mar 10, 2025 | VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java. |
| CVE-2025-26936 | CRITICAL | 10 | 0.5% | Mar 10, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework all... |
| CVE-2025-26916 | CRITICAL | 9 | 0.6% | Mar 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-2152 | CRITICAL | 9.8 | 0.5% | Mar 10, 2025 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ... |
| CVE-2025-1497 | CRITICAL | 9.8 | 1.0% | Mar 10, 2025 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-g... |
| CVE-2025-1945 | CRITICAL | 9.8 | 0.5% | Mar 10, 2025 | picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag... |
| CVE-2025-2115 | CRITICAL | 9.8 | 0.6% | Mar 9, 2025 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affec... |
| CVE-2025-2113 | CRITICAL | 9.8 | 0.5% | Mar 9, 2025 | A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this is... |
| CVE-2025-2112 | CRITICAL | 9.8 | 0.5% | Mar 8, 2025 | A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declar... |
| CVE-2025-1323 | CRITICAL | 9.8 | 2.9% | Mar 8, 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'data... |
| CVE-2025-0177 | CRITICAL | 9.8 | 0.4% | Mar 8, 2025 | The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080... |
| CVE-2025-2097 | CRITICAL | 9.8 | 6.0% | Mar 7, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue... |
| CVE-2025-2096 | CRITICAL | 9.8 | 2.7% | Mar 7, 2025 | A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects ... |
| CVE-2025-2095 | CRITICAL | 9.8 | 2.5% | Mar 7, 2025 | A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the funct... |
| CVE-2025-2094 | CRITICAL | 9.8 | 11.0% | Mar 7, 2025 | A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this is... |
| CVE-2025-27603 | CRITICAL | 9.1 | 0.6% | Mar 7, 2025 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't ... |
| CVE-2025-27519 | CRITICAL | 9.3 | 1.3% | Mar 7, 2025 | Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for productio... |
| CVE-2025-2088 | CRITICAL | 9.8 | 0.5% | Mar 7, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affec... |
| CVE-2025-1315 | CRITICAL | 9.8 | 0.5% | Mar 7, 2025 | The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now