2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1677 | HIGH | 7.5 | 0.3% | Apr 10, 2025 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and... |
| CVE-2025-1073 | HIGH | 7.5 | 0.2% | Apr 10, 2025 | Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unaut... |
| CVE-2025-27350 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice V... |
| CVE-2025-23386 | HIGH | 7.8 | 0.1% | Apr 10, 2025 | A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera... |
| CVE-2025-22279 | HIGH | 7.5 | 0.5% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32687 | HIGH | 8.5 | 0.3% | Apr 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review ... |
| CVE-2025-32668 | HIGH | 8.1 | 0.5% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32160 | HIGH | 7.5 | 0.6% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32158 | HIGH | 8.8 | 0.6% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32145 | HIGH | 8.8 | 0.4% | Apr 10, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2025-32128 | HIGH | 7.6 | 0.4% | Apr 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby L... |
| CVE-2025-32119 | HIGH | 8.2 | 0.3% | Apr 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate ... |
| CVE-2025-32116 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master q... |
| CVE-2025-32115 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping ... |
| CVE-2025-32114 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist... |
| CVE-2025-31524 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Es... |
| CVE-2025-30582 | HIGH | 8.1 | 0.6% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/C... |
| CVE-2025-3417 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati... |
| CVE-2025-2809 | HIGH | 7.3 | 0.4% | Apr 10, 2025 | The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version... |
| CVE-2025-2805 | HIGH | 7.3 | 0.4% | Apr 10, 2025 | The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,... |
| CVE-2025-0539 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests th... |
| CVE-2025-3102 | HIGH | 8.1 | 76.2% | Apr 10, 2025 | The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading ... |
| CVE-2025-26480 | HIGH | 7.5 | 0.4% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. A... |
| CVE-2025-26330 | HIGH | 7 | 0.1% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthen... |
| CVE-2025-30660 | HIGH | 8.7 | 0.3% | Apr 9, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper N... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now