2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1971 | HIGH | 7.2 | 0.7% | Mar 22, 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up ... |
| CVE-2025-1970 | HIGH | 7.6 | 0.4% | Mar 22, 2025 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi... |
| CVE-2025-2303 | HIGH | 8.8 | 0.8% | Mar 22, 2025 | The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in al... |
| CVE-2025-0724 | HIGH | 8.8 | 0.6% | Mar 22, 2025 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-30204 | HIGH | 7.5 | 0.7% | Mar 21, 2025 | golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, t... |
| CVE-2025-2608 | HIGH | 8.8 | 0.4% | Mar 21, 2025 | A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown ... |
| CVE-2025-2602 | HIGH | 8.8 | 0.4% | Mar 21, 2025 | A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri... |
| CVE-2025-2601 | HIGH | 8.8 | 0.4% | Mar 21, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management Sy... |
| CVE-2025-25035 | HIGH | 7.3 | 0.4% | Mar 21, 2025 | Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 al... |
| CVE-2025-30349 | HIGH | 7.2 | 29.2% | Mar 21, 2025 | Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take... |
| CVE-2025-29230 | HIGH | 8.6 | 0.7% | Mar 21, 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. Th... |
| CVE-2025-30157 | HIGH | 7.5 | 0.4% | Mar 21, 2025 | Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy'... |
| CVE-2025-29641 | HIGH | 7.3 | 0.2% | Mar 21, 2025 | Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' ... |
| CVE-2025-24915 | HIGH | 7.8 | 0.2% | Mar 21, 2025 | When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not ... |
| CVE-2025-2592 | HIGH | 8.8 | 0.7% | Mar 21, 2025 | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ... |
| CVE-2025-25274 | HIGH | 8.8 | 0.3% | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived ... |
| CVE-2025-25068 | HIGH | 8.8 | 0.3% | Mar 21, 2025 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin... |
| CVE-2025-30347 | HIGH | 7.5 | 0.3% | Mar 21, 2025 | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read fo... |
| CVE-2025-2581 | HIGH | 7.5 | 0.6% | Mar 21, 2025 | A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the fu... |
| CVE-2025-2585 | HIGH | 8.8 | 0.4% | Mar 21, 2025 | EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular p... |
| CVE-2025-29814 | HIGH | 8.8 | 1.9% | Mar 21, 2025 | Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-29807 | HIGH | 8.8 | 1.2% | Mar 21, 2025 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. |
| CVE-2025-30334 | HIGH | 7.1 | 0.4% | Mar 20, 2025 | In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash... |
| CVE-2025-25758 | HIGH | 7.5 | 0.3% | Mar 20, 2025 | An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBack... |
| CVE-2025-30160 | HIGH | 7.5 | 0.5% | Mar 20, 2025 | Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker ca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now