2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1104 | CRITICAL | 9.8 | 2.7% | Feb 7, 2025 | A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown ... |
| CVE-2025-1107 | CRITICAL | 9.9 | 0.4% | Feb 7, 2025 | Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker t... |
| CVE-2025-25167 | CRITICAL | 9.8 | 0.4% | Feb 7, 2025 | Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorre... |
| CVE-2025-25163 | CRITICAL | 9.8 | 1.9% | Feb 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Im... |
| CVE-2025-25107 | CRITICAL | 9.6 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forger... |
| CVE-2025-25106 | CRITICAL | 9.6 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross S... |
| CVE-2025-25101 | CRITICAL | 9.6 | 0.5% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.... |
| CVE-2025-1077 | CRITICAL | 9.5 | 0.8% | Feb 7, 2025 | A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS,... |
| CVE-2025-1061 | CRITICAL | 9.8 | 0.6% | Feb 7, 2025 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin... |
| CVE-2025-0674 | CRITICAL | 9.8 | 3.8% | Feb 7, 2025 | Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the ... |
| CVE-2025-24786 | CRITICAL | 9.1 | 2.7% | Feb 6, 2025 | WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d... |
| CVE-2025-22992 | CRITICAL | 9.8 | 0.5% | Feb 6, 2025 | A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili... |
| CVE-2025-24981 | CRITICAL | 9.3 | 0.6% | Feb 6, 2025 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions... |
| CVE-2025-0982 | CRITICAL | 10 | 0.2% | Feb 6, 2025 | Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra... |
| CVE-2025-1066 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campai... |
| CVE-2025-23114 | CRITICAL | 9 | 0.6% | Feb 5, 2025 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected ... |
| CVE-2025-0960 | CRITICAL | 9.8 | 0.8% | Feb 4, 2025 | AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an att... |
| CVE-2025-24971 | CRITICAL | 9.5 | 3.2% | Feb 4, 2025 | DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Co... |
| CVE-2025-0364 | CRITICAL | 9.8 | 1.8% | Feb 4, 2025 | BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via... |
| CVE-2025-24677 | CRITICAL | 9.9 | 0.5% | Feb 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import... |
| CVE-2025-22699 | CRITICAL | 9 | 0.4% | Feb 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-1020 | CRITICAL | 9.8 | 0.5% | Feb 4, 2025 | Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-1017 | CRITICAL | 9.8 | 0.6% | Feb 4, 2025 | Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs... |
| CVE-2025-1016 | CRITICAL | 9.8 | 0.6% | Feb 4, 2025 | Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, a... |
| CVE-2025-1009 | CRITICAL | 9.8 | 1.2% | Feb 4, 2025 | An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now