2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3872 | HIGH | 7.2 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-... |
| CVE-2025-3776 | HIGH | 8.3 | 0.7% | Apr 24, 2025 | The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions ... |
| CVE-2025-3607 | HIGH | 8.8 | 0.4% | Apr 24, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2025-3300 | HIGH | 7.2 | 0.9% | Apr 24, 2025 | The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all version... |
| CVE-2025-3101 | HIGH | 8.8 | 0.3% | Apr 24, 2025 | The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2025-3058 | HIGH | 8.8 | 0.4% | Apr 24, 2025 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es... |
| CVE-2025-1908 | HIGH | 7.7 | 0.3% | Apr 24, 2025 | An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potential... |
| CVE-2025-0639 | HIGH | 7.5 | 0.4% | Apr 24, 2025 | An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro... |
| CVE-2025-41395 | HIGH | 7.5 | 0.4% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th... |
| CVE-2025-3761 | HIGH | 8.8 | 0.3% | Apr 24, 2025 | The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions u... |
| CVE-2025-35965 | HIGH | 7.5 | 0.3% | Apr 24, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o... |
| CVE-2025-2558 | HIGH | 8.6 | 2.1% | Apr 24, 2025 | The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to ... |
| CVE-2025-46417 | HIGH | 7.5 | 0.2% | Apr 24, 2025 | The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltra... |
| CVE-2025-27580 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that de... |
| CVE-2025-46397 | HIGH | 7.8 | 0.3% | Apr 23, 2025 | A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spli... |
| CVE-2025-32818 | HIGH | 7.5 | 0.8% | Apr 23, 2025 | A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated... |
| CVE-2025-28169 | HIGH | 8.1 | 0.3% | Apr 23, 2025 | BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the ma... |
| CVE-2025-3904 | HIGH | 7.3 | 0.2% | Apr 23, 2025 | Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*. |
| CVE-2025-3903 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. |
| CVE-2025-2773 | HIGH | 7.2 | 1.8% | Apr 23, 2025 | BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2025-2769 | HIGH | 7.8 | 0.2% | Apr 23, 2025 | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc... |
| CVE-2025-2768 | HIGH | 7.8 | 0.2% | Apr 23, 2025 | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows loc... |
| CVE-2025-2765 | HIGH | 8.8 | 0.3% | Apr 23, 2025 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability al... |
| CVE-2025-2764 | HIGH | 8 | 0.2% | Apr 23, 2025 | CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vul... |
| CVE-2025-2762 | HIGH | 7.8 | 0.2% | Apr 23, 2025 | CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local at... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now