2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2058 | CRITICAL | 9.8 | 0.5% | Mar 7, 2025 | A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected ... |
| CVE-2025-2057 | CRITICAL | 9.8 | 0.6% | Mar 7, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affect... |
| CVE-2025-2050 | CRITICAL | 9.8 | 0.5% | Mar 7, 2025 | A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3.... |
| CVE-2025-2046 | CRITICAL | 9.8 | 0.4% | Mar 6, 2025 | A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-2041 | CRITICAL | 9.8 | 0.5% | Mar 6, 2025 | A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected b... |
| CVE-2025-25763 | CRITICAL | 9.8 | 0.8% | Mar 6, 2025 | crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php |
| CVE-2025-2036 | CRITICAL | 9.8 | 0.5% | Mar 6, 2025 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects a... |
| CVE-2025-27509 | CRITICAL | 9.3 | 0.6% | Mar 6, 2025 | fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could ... |
| CVE-2025-25361 | CRITICAL | 9.8 | 0.6% | Mar 6, 2025 | An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 all... |
| CVE-2025-2035 | CRITICAL | 9.8 | 0.5% | Mar 6, 2025 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue ... |
| CVE-2025-2034 | CRITICAL | 9.8 | 0.5% | Mar 6, 2025 | A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th... |
| CVE-2025-25632 | CRITICAL | 9.8 | 1.6% | Mar 5, 2025 | Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet. |
| CVE-2025-25362 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via... |
| CVE-2025-27517 | CRITICAL | 9.3 | 0.6% | Mar 5, 2025 | Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lea... |
| CVE-2025-27515 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*... |
| CVE-2025-25015 | CRITICAL | 9.9 | 1.2% | Mar 5, 2025 | Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP ... |
| CVE-2025-1515 | CRITICAL | 9.8 | 0.5% | Mar 5, 2025 | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ... |
| CVE-2025-1393 | CRITICAL | 9.8 | 0.5% | Mar 5, 2025 | An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected... |
| CVE-2025-27682 | CRITICAL | 9.8 | 0.6% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Per... |
| CVE-2025-27681 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter... |
| CVE-2025-27680 | CRITICAL | 9.1 | 0.3% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmwar... |
| CVE-2025-27678 | CRITICAL | 9.8 | 1.2% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote C... |
| CVE-2025-27677 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links ... |
| CVE-2025-27675 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable Open... |
| CVE-2025-27674 | CRITICAL | 9.8 | 0.7% | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Hardcoded IdP K... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now