2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30076 | HIGH | 7.7 | 0.4% | Mar 16, 2025 | Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl repo... |
| CVE-2025-30074 | HIGH | 7.8 | 0.1% | Mar 16, 2025 | Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation t... |
| CVE-2025-27281 | HIGH | 8.5 | 0.3% | Mar 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In ... |
| CVE-2025-26978 | HIGH | 8.5 | 0.3% | Mar 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster ... |
| CVE-2025-26976 | HIGH | 8.5 | 0.3% | Mar 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino Privat... |
| CVE-2025-26972 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateCo... |
| CVE-2025-26969 | HIGH | 8.3 | 0.3% | Mar 15, 2025 | Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8... |
| CVE-2025-26961 | HIGH | 8.6 | 0.3% | Mar 15, 2025 | Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Prop... |
| CVE-2025-26921 | HIGH | 8.8 | 0.4% | Mar 15, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-... |
| CVE-2025-26886 | HIGH | 7.6 | 0.3% | Mar 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress Publi... |
| CVE-2025-26556 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zzmaster WP AntiDD... |
| CVE-2025-26555 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thorsten Ott Debug... |
| CVE-2025-26554 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP ... |
| CVE-2025-26553 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spring Devs Pre Or... |
| CVE-2025-26548 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kdmurray Random Im... |
| CVE-2025-23744 | HIGH | 7.1 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dvs11 Random Posts... |
| CVE-2025-2025 | HIGH | 7.5 | 0.6% | Mar 15, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data ... |
| CVE-2025-30066 | HIGH | 8.6 | 41.0% | Mar 15, 2025 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr... |
| CVE-2025-1657 | HIGH | 8.8 | 0.4% | Mar 15, 2025 | The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2025-1653 | HIGH | 8.8 | 0.5% | Mar 15, 2025 | The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all ver... |
| CVE-2025-2310 | HIGH | 7.8 | 0.4% | Mar 14, 2025 | A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the... |
| CVE-2025-2309 | HIGH | 7.8 | 0.3% | Mar 14, 2025 | A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__b... |
| CVE-2025-2308 | HIGH | 7.8 | 0.4% | Mar 14, 2025 | A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_... |
| CVE-2025-29387 | HIGH | 7.1 | 0.5% | Mar 14, 2025 | In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerabili... |
| CVE-2025-25871 | HIGH | 8 | 0.4% | Mar 14, 2025 | An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now