2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58059 | CRITICAL | 9.1 | 0.4% | Aug 28, 2025 | Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be... |
| CVE-2025-58048 | CRITICAL | 9.9 | 0.4% | Aug 28, 2025 | Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments funct... |
| CVE-2025-57819 | CRITICAL | 9.8 | 85.5% | Aug 28, 2025 | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins... |
| CVE-2025-55583 | CRITICAL | 9.8 | 5.8% | Aug 28, 2025 | D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in... |
| CVE-2025-54738 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth... |
| CVE-2025-54725 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th... |
| CVE-2025-54720 | CRITICAL | 9.3 | 0.3% | Aug 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest A... |
| CVE-2025-52761 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection... |
| CVE-2025-49388 | CRITICAL | 9.8 | 5.0% | Aug 28, 2025 | Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Esca... |
| CVE-2025-49387 | CRITICAL | 10 | 0.4% | Aug 28, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor For... |
| CVE-2025-48100 | CRITICAL | 9.1 | 0.3% | Aug 28, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu... |
| CVE-2025-39496 | CRITICAL | 9.3 | 0.3% | Aug 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ... |
| CVE-2025-54762 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-53970 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-7955 | CRITICAL | 9.8 | 0.7% | Aug 28, 2025 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi... |
| CVE-2025-34523 | CRITICAL | 9.8 | 0.5% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data... |
| CVE-2025-34522 | CRITICAL | 9.8 | 0.6% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ... |
| CVE-2025-34520 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai... |
| CVE-2025-34163 | CRITICAL | 10 | 0.7% | Aug 27, 2025 | Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ... |
| CVE-2025-34162 | CRITICAL | 9.3 | 0.6% | Aug 27, 2025 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme... |
| CVE-2025-34160 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port... |
| CVE-2025-58050 | CRITICAL | 9.1 | 0.7% | Aug 27, 2025 | The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b... |
| CVE-2025-50428 | CRITICAL | 9.8 | 1.6% | Aug 27, 2025 | In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ... |
| CVE-2025-34157 | CRITICAL | 9 | 0.4% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ... |
| CVE-2025-9533 | CRITICAL | 9.8 | 9.2% | Aug 27, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now