2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3617 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files a... |
| CVE-2025-33027 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers... |
| CVE-2025-33026 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass... |
| CVE-2025-32780 | HIGH | 7.3 | 0.2% | Apr 15, 2025 | BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerab... |
| CVE-2025-32948 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send request... |
| CVE-2025-32947 | HIGH | 7.5 | 0.6% | Apr 15, 2025 | This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite lo... |
| CVE-2025-29281 | HIGH | 8.8 | 0.6% | Apr 15, 2025 | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component... |
| CVE-2025-32929 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-bar... |
| CVE-2025-31011 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers S... |
| CVE-2025-30962 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster ... |
| CVE-2025-26992 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing... |
| CVE-2025-26959 | HIGH | 8.8 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue ... |
| CVE-2025-26958 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrain... |
| CVE-2025-26954 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooE... |
| CVE-2025-26944 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetPopup jet-popup allows Accessing Functionality Not Properly Constra... |
| CVE-2025-26942 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Const... |
| CVE-2025-26894 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26889 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26743 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Qu... |
| CVE-2025-26741 | HIGH | 8.8 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Pri... |
| CVE-2025-3575 | HIGH | 8.7 | 0.4% | Apr 15, 2025 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor... |
| CVE-2025-3574 | HIGH | 8.7 | 0.4% | Apr 15, 2025 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor... |
| CVE-2025-29984 | HIGH | 7.3 | 0.1% | Apr 15, 2025 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privilege... |
| CVE-2025-29983 | HIGH | 7.3 | 0.1% | Apr 15, 2025 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following'... |
| CVE-2025-31491 | HIGH | 8.6 | 0.4% | Apr 15, 2025 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now