2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3540 | HIGH | 8.6 | 1.3% | Apr 13, 2025 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V1... |
| CVE-2025-3539 | HIGH | 8.6 | 1.3% | Apr 13, 2025 | A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Ma... |
| CVE-2025-3445 | HIGH | 8.1 | 0.4% | Apr 13, 2025 | A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a... |
| CVE-2025-3538 | HIGH | 8.8 | 8.3% | Apr 13, 2025 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function a... |
| CVE-2025-3418 | HIGH | 8.8 | 0.3% | Apr 12, 2025 | The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due... |
| CVE-2025-29834 | HIGH | 7.5 | 0.5% | Apr 12, 2025 | Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29803 | HIGH | 7.3 | 0.6% | Apr 12, 2025 | Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an auth... |
| CVE-2025-32367 | HIGH | 8.6 | 0.4% | Apr 11, 2025 | The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure D... |
| CVE-2025-23389 | HIGH | 8.4 | 0.4% | Apr 11, 2025 | A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML... |
| CVE-2025-23388 | HIGH | 8.2 | 0.5% | Apr 11, 2025 | A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: fro... |
| CVE-2025-31932 | HIGH | 8.8 | 0.6% | Apr 11, 2025 | Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrar... |
| CVE-2025-3434 | HIGH | 7.2 | 0.4% | Apr 11, 2025 | The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in al... |
| CVE-2025-32681 | HIGH | 8.5 | 0.4% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log ... |
| CVE-2025-32672 | HIGH | 8.1 | 0.8% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32671 | HIGH | 7.5 | 0.6% | Apr 11, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Sci... |
| CVE-2025-32663 | HIGH | 8.1 | 0.8% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32656 | HIGH | 8.1 | 0.8% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32654 | HIGH | 8.1 | 0.8% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32650 | HIGH | 8.5 | 0.4% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Acces... |
| CVE-2025-32633 | HIGH | 8.6 | 0.6% | Apr 11, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset... |
| CVE-2025-32632 | HIGH | 7.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Autom... |
| CVE-2025-32631 | HIGH | 8.6 | 0.6% | Apr 11, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in oxygensuite Oxygen MyDat... |
| CVE-2025-32629 | HIGH | 8.6 | 0.6% | Apr 11, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Bu... |
| CVE-2025-32627 | HIGH | 8.1 | 0.8% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32618 | HIGH | 8.5 | 0.4% | Apr 11, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishli... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now