2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22018 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_... |
| CVE-2025-3666 | MEDIUM | 6.9 | 0.5% | Apr 16, 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is... |
| CVE-2025-3665 | MEDIUM | 6.9 | 0.5% | Apr 16, 2025 | A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vul... |
| CVE-2025-3664 | MEDIUM | 6.9 | 0.5% | Apr 16, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the f... |
| CVE-2025-2314 | MEDIUM | 6.4 | 0.3% | Apr 16, 2025 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2025-32385 | MEDIUM | 6.5 | 0.2% | Apr 16, 2025 | EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to displ... |
| CVE-2025-32388 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsa... |
| CVE-2025-25458 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2. |
| CVE-2025-25453 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2. |
| CVE-2025-22911 | MEDIUM | 5.6 | 0.3% | Apr 15, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function. |
| CVE-2025-32782 | MEDIUM | 5.3 | 0.3% | Apr 15, 2025 | Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently u... |
| CVE-2025-31950 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger energy consumption information of other users. |
| CVE-2025-31945 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | An unauthenticated attacker can obtain other users' charger information. |
| CVE-2025-31654 | MEDIUM | 6.9 | 0.2% | Apr 15, 2025 | An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). |
| CVE-2025-31147 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. |
| CVE-2025-30982 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookPr... |
| CVE-2025-30966 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a throu... |
| CVE-2025-30512 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g.... |
| CVE-2025-30257 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. |
| CVE-2025-27929 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. |
| CVE-2025-27927 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. |
| CVE-2025-27892 | MEDIUM | 6.8 | 11.3% | Apr 15, 2025 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:... |
| CVE-2025-27719 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | Unauthenticated attackers can query an API endpoint and get device details. |
| CVE-2025-27575 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. |
| CVE-2025-27565 | MEDIUM | 5.3 | 0.2% | Apr 15, 2025 | An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now