2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25570 | CRITICAL | 9.8 | 2.0% | Feb 27, 2025 | Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. |
| CVE-2025-22952 | CRITICAL | 9.8 | 2.8% | Feb 27, 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie... |
| CVE-2025-0767 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in ... |
| CVE-2025-27154 | CRITICAL | 9.8 | 0.6% | Feb 27, 2025 | Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store ... |
| CVE-2025-1751 | CRITICAL | 9.8 | 0.5% | Feb 27, 2025 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t... |
| CVE-2025-21796 | CRITICAL | 9.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing ... |
| CVE-2025-25790 | CRITICAL | 9.8 | 1.0% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers ... |
| CVE-2025-25789 | CRITICAL | 9.8 | 1.5% | Feb 26, 2025 | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controlle... |
| CVE-2025-25785 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.ph... |
| CVE-2025-25784 | CRITICAL | 9.8 | 1.0% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to... |
| CVE-2025-25783 | CRITICAL | 9.8 | 0.8% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute... |
| CVE-2025-1716 | CRITICAL | 9.8 | 1.5% | Feb 26, 2025 | picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses P... |
| CVE-2025-25521 | CRITICAL | 9.8 | 0.5% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. |
| CVE-2025-25520 | CRITICAL | 9.8 | 0.5% | Feb 25, 2025 | Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. |
| CVE-2025-25519 | CRITICAL | 9.8 | 0.5% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. |
| CVE-2025-25517 | CRITICAL | 9.8 | 0.5% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. |
| CVE-2025-25516 | CRITICAL | 9.8 | 0.5% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. |
| CVE-2025-27135 | CRITICAL | 9.8 | 0.6% | Feb 25, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL i... |
| CVE-2025-26974 | CRITICAL | 9.3 | 0.5% | Feb 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Mu... |
| CVE-2025-26971 | CRITICAL | 9.8 | 0.4% | Feb 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker... |
| CVE-2025-26966 | CRITICAL | 9.8 | 0.6% | Feb 25, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.Thi... |
| CVE-2025-26943 | CRITICAL | 9.3 | 0.5% | Feb 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy... |
| CVE-2025-26900 | CRITICAL | 9.8 | 0.6% | Feb 25, 2025 | Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue a... |
| CVE-2025-1676 | CRITICAL | 9.8 | 2.4% | Feb 25, 2025 | A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulne... |
| CVE-2025-1675 | CRITICAL | 9.1 | 0.4% | Feb 25, 2025 | The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not chec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now