2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3803 | HIGH | 8.8 | 0.8% | Apr 19, 2025 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue af... |
| CVE-2025-3802 | HIGH | 8.8 | 0.8% | Apr 19, 2025 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulne... |
| CVE-2025-3798 | HIGH | 7.2 | 0.4% | Apr 19, 2025 | A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the... |
| CVE-2025-3404 | HIGH | 8.8 | 0.9% | Apr 19, 2025 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2025-3797 | HIGH | 7.2 | 0.4% | Apr 19, 2025 | A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the fi... |
| CVE-2025-3809 | HIGH | 7.2 | 0.2% | Apr 19, 2025 | The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log i... |
| CVE-2025-2111 | HIGH | 7.5 | 0.2% | Apr 19, 2025 | The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-3103 | HIGH | 7.5 | 0.3% | Apr 19, 2025 | The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu... |
| CVE-2025-2010 | HIGH | 7.5 | 1.5% | Apr 19, 2025 | The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2025-3796 | HIGH | 8.8 | 0.4% | Apr 18, 2025 | A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unk... |
| CVE-2025-32953 | HIGH | 8.7 | 0.4% | Apr 18, 2025 | z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubunt... |
| CVE-2025-24914 | HIGH | 7.8 | 0.1% | Apr 18, 2025 | When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu... |
| CVE-2025-28237 | HIGH | 8.8 | 0.3% | Apr 18, 2025 | An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges... |
| CVE-2025-28235 | HIGH | 7.5 | 0.3% | Apr 18, 2025 | An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 a... |
| CVE-2025-1697 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products... |
| CVE-2025-28059 | HIGH | 7.5 | 0.7% | Apr 18, 2025 | An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system re... |
| CVE-2025-32792 | HIGH | 8.7 | 0.4% | Apr 18, 2025 | SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their... |
| CVE-2025-32442 | HIGH | 7.5 | 0.6% | Apr 18, 2025 | Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, app... |
| CVE-2025-31118 | HIGH | 7.1 | 0.4% | Apr 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum q... |
| CVE-2025-30158 | HIGH | 7.1 | 0.4% | Apr 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the for... |
| CVE-2025-29784 | HIGH | 7.5 | 0.5% | Apr 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p... |
| CVE-2025-3792 | HIGH | 7.2 | 0.5% | Apr 18, 2025 | A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown ... |
| CVE-2025-37838 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability... |
| CVE-2025-29625 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Servic... |
| CVE-2025-28228 | HIGH | 7.5 | 1.6% | Apr 18, 2025 | A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now