2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0926 | HIGH | 7.3 | 0.2% | Apr 23, 2025 | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to ... |
| CVE-2025-1021 | HIGH | 7.5 | 0.5% | Apr 23, 2025 | Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-... |
| CVE-2025-29621 | HIGH | 7.3 | 0.2% | Apr 22, 2025 | Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuratio... |
| CVE-2025-43950 | HIGH | 7.8 | 0.2% | Apr 22, 2025 | DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence... |
| CVE-2025-43948 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or... |
| CVE-2025-43947 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions ... |
| CVE-2025-28029 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28027 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28026 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-29339 | HIGH | 7.5 | 0.4% | Apr 22, 2025 | An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session paramete... |
| CVE-2025-3767 | HIGH | 7.2 | 0.3% | Apr 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Bool... |
| CVE-2025-28030 | HIGH | 8.8 | 0.4% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime paramete... |
| CVE-2025-29547 | HIGH | 7 | 0.3% | Apr 22, 2025 | In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service becaus... |
| CVE-2025-23176 | HIGH | 8.8 | 0.4% | Apr 22, 2025 | CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2025-1950 | HIGH | 7.8 | 0.2% | Apr 22, 2025 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman... |
| CVE-2025-28033 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-28032 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51... |
| CVE-2025-2092 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 ... |
| CVE-2025-46252 | HIGH | 7.2 | 0.4% | Apr 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Messag... |
| CVE-2025-46251 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forg... |
| CVE-2025-46249 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor a... |
| CVE-2025-46246 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Reques... |
| CVE-2025-46245 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site ... |
| CVE-2025-46243 | HIGH | 8.8 | 0.1% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abando... |
| CVE-2025-46241 | HIGH | 8.8 | 0.2% | Apr 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now