2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0890 | CRITICAL | 9.8 | 12.8% | Feb 4, 2025 | **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B... |
| CVE-2025-22204 | CRITICAL | 9.8 | 0.7% | Feb 4, 2025 | Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote ... |
| CVE-2025-24957 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24906 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24905 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24370 | CRITICAL | 9.3 | 0.5% | Feb 3, 2025 | Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are... |
| CVE-2025-22978 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module. |
| CVE-2025-20634 | CRITICAL | 9.8 | 0.7% | Feb 3, 2025 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio... |
| CVE-2025-0950 | CRITICAL | 9.8 | 0.4% | Feb 1, 2025 | A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects... |
| CVE-2025-0946 | CRITICAL | 9.8 | 0.5% | Feb 1, 2025 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne... |
| CVE-2025-0945 | CRITICAL | 9.8 | 0.5% | Feb 1, 2025 | A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an un... |
| CVE-2025-0944 | CRITICAL | 9.8 | 1.0% | Feb 1, 2025 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue aff... |
| CVE-2025-0943 | CRITICAL | 9.8 | 0.5% | Feb 1, 2025 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulner... |
| CVE-2025-24891 | CRITICAL | 9.6 | 0.6% | Jan 31, 2025 | Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver... |
| CVE-2025-22957 | CRITICAL | 9.8 | 0.5% | Jan 31, 2025 | A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without an... |
| CVE-2025-23215 | CRITICAL | 9.3 | 0.3% | Jan 31, 2025 | PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing key... |
| CVE-2025-0929 | CRITICAL | 9.8 | 0.8% | Jan 31, 2025 | SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete a... |
| CVE-2025-0493 | CRITICAL | 9.8 | 1.0% | Jan 31, 2025 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limit... |
| CVE-2025-0881 | CRITICAL | 9.8 | 0.4% | Jan 30, 2025 | A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unkn... |
| CVE-2025-0880 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unkn... |
| CVE-2025-0147 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation o... |
| CVE-2025-24503 | CRITICAL | 9.3 | 0.2% | Jan 30, 2025 | A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM... |
| CVE-2025-0680 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attac... |
| CVE-2025-0874 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management ... |
| CVE-2025-0498 | CRITICAL | 9.8 | 0.4% | Jan 30, 2025 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now