2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32365 | HIGH | 7.1 | 0.2% | Apr 5, 2025 | Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in... |
| CVE-2025-3303 | HIGH | 7.5 | 0.4% | Apr 5, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0.... |
| CVE-2025-32360 | HIGH | 8.1 | 0.2% | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared articl... |
| CVE-2025-32359 | HIGH | 8.8 | 0.3% | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor a... |
| CVE-2025-3299 | HIGH | 7.3 | 0.4% | Apr 5, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this iss... |
| CVE-2025-2933 | HIGH | 8.8 | 0.3% | Apr 5, 2025 | The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lea... |
| CVE-2025-0810 | HIGH | 7.5 | 0.2% | Apr 5, 2025 | The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-1500 | HIGH | 8 | 0.2% | Apr 5, 2025 | IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be e... |
| CVE-2025-3267 | HIGH | 8.8 | 0.4% | Apr 4, 2025 | A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknow... |
| CVE-2025-3259 | HIGH | 8.8 | 0.9% | Apr 4, 2025 | A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the funct... |
| CVE-2025-3256 | HIGH | 7.5 | 0.3% | Apr 4, 2025 | A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unkn... |
| CVE-2025-3255 | HIGH | 7.5 | 0.5% | Apr 4, 2025 | A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerabilit... |
| CVE-2025-32280 | HIGH | 8.8 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Re... |
| CVE-2025-32220 | HIGH | 8.8 | 0.5% | Apr 4, 2025 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorr... |
| CVE-2025-32204 | HIGH | 7.6 | 0.5% | Apr 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rocketelements Spl... |
| CVE-2025-32203 | HIGH | 7.6 | 0.6% | Apr 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in manu225 Falling th... |
| CVE-2025-32159 | HIGH | 7.5 | 0.9% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32157 | HIGH | 7.5 | 1.0% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32156 | HIGH | 7.5 | 1.0% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32155 | HIGH | 7.5 | 0.8% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32154 | HIGH | 8.8 | 0.8% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32153 | HIGH | 7.5 | 1.0% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32152 | HIGH | 7.5 | 1.0% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32151 | HIGH | 8.8 | 0.8% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32150 | HIGH | 7.5 | 1.0% | Apr 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now