2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2761 | HIGH | 7.8 | 1.4% | Apr 23, 2025 | GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacker... |
| CVE-2025-2760 | HIGH | 7.8 | 6.3% | Apr 23, 2025 | GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2025-28028 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28025 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28022 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ... |
| CVE-2025-28021 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi thro... |
| CVE-2025-28020 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ... |
| CVE-2025-28019 | HIGH | 7.3 | 0.4% | Apr 23, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi comp... |
| CVE-2025-28018 | HIGH | 7.3 | 0.3% | Apr 23, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through ... |
| CVE-2025-1520 | HIGH | 8 | 0.4% | Apr 23, 2025 | PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-... |
| CVE-2025-1050 | HIGH | 8.8 | 0.4% | Apr 23, 2025 | Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack... |
| CVE-2025-1049 | HIGH | 8.8 | 0.4% | Apr 23, 2025 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent... |
| CVE-2025-1048 | HIGH | 8.8 | 0.5% | Apr 23, 2025 | Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adja... |
| CVE-2025-1047 | HIGH | 7.8 | 0.3% | Apr 23, 2025 | Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-1046 | HIGH | 7.8 | 0.3% | Apr 23, 2025 | Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2025-1045 | HIGH | 7.8 | 0.3% | Apr 23, 2025 | Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2025-32968 | HIGH | 8.8 | 0.4% | Apr 23, 2025 | XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it ... |
| CVE-2025-21605 | HIGH | 7.5 | 0.8% | Apr 23, 2025 | Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An un... |
| CVE-2025-43965 | HIGH | 7.5 | 0.5% | Apr 23, 2025 | In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. |
| CVE-2025-42603 | HIGH | 8.7 | 0.3% | Apr 23, 2025 | This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the respo... |
| CVE-2025-42602 | HIGH | 8.2 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API end... |
| CVE-2025-42601 | HIGH | 8.2 | 0.3% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API... |
| CVE-2025-42600 | HIGH | 8.2 | 0.4% | Apr 23, 2025 | This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password... |
| CVE-2025-3530 | HIGH | 7.5 | 0.4% | Apr 23, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t... |
| CVE-2025-3529 | HIGH | 8.2 | 0.3% | Apr 23, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now