2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22282 | HIGH | 7.1 | 0.2% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keksdieb ez Form C... |
| CVE-2025-2243 | HIGH | 7.3 | 0.3% | Apr 4, 2025 | A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input... |
| CVE-2025-1865 | HIGH | 8.5 | 0.1% | Apr 4, 2025 | The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges... |
| CVE-2025-3229 | HIGH | 7.2 | 0.4% | Apr 4, 2025 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vuln... |
| CVE-2025-3105 | HIGH | 8.8 | 0.3% | Apr 4, 2025 | The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privil... |
| CVE-2025-3215 | HIGH | 8.8 | 0.4% | Apr 4, 2025 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this... |
| CVE-2025-3086 | HIGH | 7.1 | 0.4% | Apr 4, 2025 | Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous ... |
| CVE-2025-32111 | HIGH | 8.7 | 0.4% | Apr 4, 2025 | The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-cred... |
| CVE-2025-2780 | HIGH | 8.8 | 0.7% | Apr 4, 2025 | The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing... |
| CVE-2025-3211 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affect... |
| CVE-2025-2317 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend para... |
| CVE-2025-2270 | HIGH | 8.1 | 1.1% | Apr 4, 2025 | The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion i... |
| CVE-2025-3210 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected... |
| CVE-2025-3208 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Aff... |
| CVE-2025-3197 | HIGH | 7.3 | 0.4% | Apr 4, 2025 | Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index... |
| CVE-2025-3194 | HIGH | 7.7 | 0.5% | Apr 4, 2025 | Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attacke... |
| CVE-2025-3192 | HIGH | 8.2 | 0.3% | Apr 4, 2025 | Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl... |
| CVE-2025-2075 | HIGH | 8.8 | 2.2% | Apr 4, 2025 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to ... |
| CVE-2025-3207 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a... |
| CVE-2025-3206 | HIGH | 7.5 | 0.4% | Apr 4, 2025 | A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerab... |
| CVE-2025-3205 | HIGH | 8.8 | 0.4% | Apr 4, 2025 | A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an un... |
| CVE-2025-29815 | HIGH | 7.6 | 0.7% | Apr 4, 2025 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2025-25000 | HIGH | 8.8 | 0.9% | Apr 4, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2025-30370 | HIGH | 7.4 | 0.5% | Apr 3, 2025 | jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Gi... |
| CVE-2025-3177 | HIGH | 8.1 | 0.4% | Apr 3, 2025 | A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now