2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32144 | HIGH | 8.8 | 0.8% | Apr 11, 2025 | Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injecti... |
| CVE-2025-32143 | HIGH | 8.8 | 0.8% | Apr 11, 2025 | Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue a... |
| CVE-2025-32107 | HIGH | 8 | 2.0% | Apr 11, 2025 | OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build ... |
| CVE-2025-31379 | HIGH | 7.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in programphases Inse... |
| CVE-2025-31378 | HIGH | 7.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in danbwb Oppso Unit ... |
| CVE-2025-31041 | HIGH | 7.5 | 0.5% | Apr 11, 2025 | Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows E... |
| CVE-2025-31040 | HIGH | 8.1 | 0.9% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31028 | HIGH | 7.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huseyin Berberoglu... |
| CVE-2025-31021 | HIGH | 7.1 | 0.3% | Apr 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dolby_uk Mobile Sm... |
| CVE-2025-31015 | HIGH | 7.5 | 0.7% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31014 | HIGH | 7.5 | 0.9% | Apr 11, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-2636 | HIGH | 8.1 | 10.1% | Apr 11, 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all v... |
| CVE-2025-0128 | HIGH | 8.7 | 0.3% | Apr 11, 2025 | A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of P... |
| CVE-2025-0127 | HIGH | 7.1 | 0.6% | Apr 11, 2025 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas... |
| CVE-2025-0126 | HIGH | 8.3 | 0.3% | Apr 11, 2025 | When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to imperson... |
| CVE-2025-0120 | HIGH | 7 | 0.1% | Apr 11, 2025 | A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices al... |
| CVE-2025-32808 | HIGH | 7.7 | 0.3% | Apr 11, 2025 | W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into t... |
| CVE-2025-29915 | HIGH | 7.5 | 0.2% | Apr 10, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th... |
| CVE-2025-23010 | HIGH | 7.2 | 0.4% | Apr 10, 2025 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and... |
| CVE-2025-23009 | HIGH | 7.2 | 0.3% | Apr 10, 2025 | A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attac... |
| CVE-2025-23008 | HIGH | 7.2 | 0.3% | Apr 10, 2025 | An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low ... |
| CVE-2025-32383 | HIGH | 7.2 | 0.2% | Apr 10, 2025 | MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model an... |
| CVE-2025-29017 | HIGH | 8.8 | 0.7% | Apr 10, 2025 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file uplo... |
| CVE-2025-27813 | HIGH | 8.1 | 0.1% | Apr 10, 2025 | MSI Center before 2.0.52.0 has Missing PE Signature Validation. |
| CVE-2025-27812 | HIGH | 8.1 | 0.1% | Apr 10, 2025 | MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now