2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31904 | HIGH | 7.1 | 0.1% | Apr 1, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Reque... |
| CVE-2025-31828 | HIGH | 8.8 | 0.2% | Apr 1, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site R... |
| CVE-2025-31132 | HIGH | 8.1 | 0.5% | Apr 1, 2025 | Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoi... |
| CVE-2025-31131 | HIGH | 7.5 | 5.4% | Apr 1, 2025 | YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read ... |
| CVE-2025-28398 | HIGH | 7.1 | 0.5% | Apr 1, 2025 | D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter. |
| CVE-2025-28395 | HIGH | 7.1 | 0.5% | Apr 1, 2025 | D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter. |
| CVE-2025-3034 | HIGH | 8.1 | 0.4% | Apr 1, 2025 | Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-3033 | HIGH | 7.7 | 0.2% | Apr 1, 2025 | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *... |
| CVE-2025-3032 | HIGH | 7.4 | 0.3% | Apr 1, 2025 | Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. ... |
| CVE-2025-3030 | HIGH | 8.1 | 0.4% | Apr 1, 2025 | Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs... |
| CVE-2025-3029 | HIGH | 7.3 | 0.3% | Apr 1, 2025 | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a poten... |
| CVE-2025-22231 | HIGH | 7.8 | 0.1% | Apr 1, 2025 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative ... |
| CVE-2025-1660 | HIGH | 7.8 | 0.2% | Apr 1, 2025 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A... |
| CVE-2025-1659 | HIGH | 7.8 | 0.2% | Apr 1, 2025 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability.... |
| CVE-2025-1658 | HIGH | 7.8 | 0.2% | Apr 1, 2025 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability.... |
| CVE-2025-3083 | HIGH | 7.5 | 0.4% | Apr 1, 2025 | Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur ... |
| CVE-2025-27130 | HIGH | 8.8 | 0.4% | Apr 1, 2025 | Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnera... |
| CVE-2025-2891 | HIGH | 8.8 | 0.6% | Apr 1, 2025 | The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-31415 | HIGH | 7.6 | 0.3% | Apr 1, 2025 | Missing Authorization vulnerability in YayCommerce YayExtra yayextra allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-31074 | HIGH | 8.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This... |
| CVE-2025-31024 | HIGH | 8.5 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Qui... |
| CVE-2025-31001 | HIGH | 7.5 | 0.4% | Apr 1, 2025 | Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sen... |
| CVE-2025-30924 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Pri... |
| CVE-2025-30917 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham SKU Genera... |
| CVE-2025-30910 | HIGH | 8.6 | 0.5% | Apr 1, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now