2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1791 | CRITICAL | 9.8 | 0.4% | Mar 1, 2025 | A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the functio... |
| CVE-2025-1671 | CRITICAL | 9.8 | 0.5% | Mar 1, 2025 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including... |
| CVE-2025-1638 | CRITICAL | 9.8 | 0.6% | Mar 1, 2025 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including... |
| CVE-2025-1564 | CRITICAL | 9.8 | 0.5% | Mar 1, 2025 | The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t... |
| CVE-2025-27554 | CRITICAL | 9.9 | 0.7% | Mar 1, 2025 | ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to exec... |
| CVE-2025-23116 | CRITICAL | 9.6 | 0.5% | Mar 1, 2025 | An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a... |
| CVE-2025-23115 | CRITICAL | 9 | 0.7% | Mar 1, 2025 | A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor w... |
| CVE-2025-25379 | CRITICAL | 9.6 | 0.3% | Feb 28, 2025 | Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the ... |
| CVE-2025-0160 | CRITICAL | 9.8 | 0.5% | Feb 28, 2025 | IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5... |
| CVE-2025-0159 | CRITICAL | 9.1 | 0.8% | Feb 28, 2025 | IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5... |
| CVE-2025-22273 | CRITICAL | 9.3 | 0.6% | Feb 28, 2025 | Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the... |
| CVE-2025-1570 | CRITICAL | 9.8 | 0.4% | Feb 28, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-1744 | CRITICAL | 9.8 | 0.5% | Feb 28, 2025 | Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issu... |
| CVE-2025-26325 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php. |
| CVE-2025-25570 | CRITICAL | 9.8 | 2.0% | Feb 27, 2025 | Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. |
| CVE-2025-22952 | CRITICAL | 9.8 | 2.8% | Feb 27, 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie... |
| CVE-2025-0767 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in ... |
| CVE-2025-27154 | CRITICAL | 9.8 | 0.6% | Feb 27, 2025 | Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store ... |
| CVE-2025-1751 | CRITICAL | 9.8 | 0.5% | Feb 27, 2025 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t... |
| CVE-2025-21796 | CRITICAL | 9.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing ... |
| CVE-2025-25790 | CRITICAL | 9.8 | 1.0% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers ... |
| CVE-2025-25789 | CRITICAL | 9.8 | 1.5% | Feb 26, 2025 | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controlle... |
| CVE-2025-25785 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.ph... |
| CVE-2025-25784 | CRITICAL | 9.8 | 1.0% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to... |
| CVE-2025-25783 | CRITICAL | 9.8 | 0.8% | Feb 26, 2025 | An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now