2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2984 | HIGH | 8.8 | 0.4% | Mar 31, 2025 | A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this is... |
| CVE-2025-3019 | HIGH | 7.2 | 0.3% | Mar 31, 2025 | KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a m... |
| CVE-2025-2402 | HIGH | 8.6 | 0.4% | Mar 31, 2025 | A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones lis... |
| CVE-2025-31387 | HIGH | 7.5 | 0.5% | Mar 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31016 | HIGH | 7.5 | 0.5% | Mar 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30855 | HIGH | 7.5 | 0.3% | Mar 31, 2025 | Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectl... |
| CVE-2025-30835 | HIGH | 7.5 | 0.5% | Mar 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31103 | HIGH | 7.5 | 0.5% | Mar 31, 2025 | Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbi... |
| CVE-2025-24517 | HIGH | 7.5 | 0.8% | Mar 31, 2025 | Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is expl... |
| CVE-2025-3014 | HIGH | 8.3 | 0.3% | Mar 31, 2025 | Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an ... |
| CVE-2025-3013 | HIGH | 8.3 | 0.3% | Mar 31, 2025 | Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Test... |
| CVE-2025-2960 | HIGH | 7.1 | 0.7% | Mar 30, 2025 | A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affe... |
| CVE-2025-2959 | HIGH | 7.1 | 0.7% | Mar 30, 2025 | A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is th... |
| CVE-2025-2958 | HIGH | 7.1 | 0.7% | Mar 30, 2025 | A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnera... |
| CVE-2025-2957 | HIGH | 7.1 | 0.3% | Mar 30, 2025 | A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function ... |
| CVE-2025-2956 | HIGH | 7.1 | 0.3% | Mar 30, 2025 | A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects th... |
| CVE-2025-1736 | HIGH | 7.3 | 0.5% | Mar 30, 2025 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-... |
| CVE-2025-2803 | HIGH | 7.3 | 0.4% | Mar 29, 2025 | The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and ... |
| CVE-2025-2249 | HIGH | 8.8 | 0.6% | Mar 29, 2025 | The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-2006 | HIGH | 8.8 | 0.7% | Mar 29, 2025 | The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ext... |
| CVE-2025-2919 | HIGH | 7 | 0.3% | Mar 28, 2025 | A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unkno... |
| CVE-2025-2917 | HIGH | 7.5 | 0.7% | Mar 28, 2025 | A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function rea... |
| CVE-2025-2713 | HIGH | 7.8 | 0.1% | Mar 28, 2025 | Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file a... |
| CVE-2025-30211 | HIGH | 7.5 | 0.4% | Mar 28, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.... |
| CVE-2025-29928 | HIGH | 8 | 0.3% | Mar 28, 2025 | authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now