2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31099 | HIGH | 7.6 | 0.3% | Mar 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestweblayout Slid... |
| CVE-2025-27932 | HIGH | 8.1 | 0.5% | Mar 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process... |
| CVE-2025-27718 | HIGH | 8.8 | 0.8% | Mar 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process o... |
| CVE-2025-2485 | HIGH | 8.8 | 0.5% | Mar 28, 2025 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in ... |
| CVE-2025-2328 | HIGH | 8.8 | 0.9% | Mar 28, 2025 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion ... |
| CVE-2025-24386 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24385 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24381 | HIGH | 8.8 | 1.3% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A... |
| CVE-2025-24380 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24379 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24378 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24377 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-23383 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-24382 | HIGH | 7.3 | 1.2% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-1860 | HIGH | 7.7 | 0.2% | Mar 28, 2025 | Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptogr... |
| CVE-2025-30232 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. |
| CVE-2025-26956 | HIGH | 7.6 | 0.2% | Mar 27, 2025 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.... |
| CVE-2025-26890 | HIGH | 7.5 | 0.6% | Mar 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26874 | HIGH | 7.1 | 0.2% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in memberspace Member... |
| CVE-2025-26733 | HIGH | 8.2 | 0.3% | Mar 27, 2025 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.... |
| CVE-2025-30093 | HIGH | 8.1 | 0.3% | Mar 27, 2025 | HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authentic... |
| CVE-2025-2855 | HIGH | 7.2 | 0.5% | Mar 27, 2025 | A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue... |
| CVE-2025-29072 | HIGH | 7.5 | 0.5% | Mar 27, 2025 | An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-l... |
| CVE-2025-28135 | HIGH | 7.5 | 0.5% | Mar 27, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi. |
| CVE-2025-22783 | HIGH | 8.8 | 0.6% | Mar 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO P... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now