2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-58059CRITICAL9.1Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be...
CVE-2025-58048CRITICAL9.9Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments funct...
CVE-2025-57819CRITICAL9.8FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins...
CVE-2025-55583CRITICAL9.8D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in...
CVE-2025-54738CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth...
CVE-2025-54725CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th...
CVE-2025-54720CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest A...
CVE-2025-52761CRITICAL9.8Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection...
CVE-2025-49388CRITICAL9.8Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Esca...
CVE-2025-49387CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor For...
CVE-2025-48100CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu...
CVE-2025-39496CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ...
CVE-2025-54762CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-53970CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-7955CRITICAL9.8The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi...
CVE-2025-34523CRITICAL9.8A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data...
CVE-2025-34522CRITICAL9.8A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ...
CVE-2025-34520CRITICAL9.8An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai...
CVE-2025-34163CRITICAL10Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ...
CVE-2025-34162CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme...
CVE-2025-34160CRITICAL10AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port...
CVE-2025-58050CRITICAL9.1The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b...
CVE-2025-50428CRITICAL9.8In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ...
CVE-2025-34157CRITICAL9Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ...
CVE-2025-9533CRITICAL9.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now