2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-9287CRITICAL9.1Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: th...
CVE-2025-8611CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-8610CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-55444CRITICAL9.8A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts...
CVE-2025-50904CRITICAL9.8There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can...
CVE-2025-50901CRITICAL9.8JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, whi...
CVE-2025-9074CRITICAL9.3A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine ...
CVE-2025-32010CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A spe...
CVE-2025-31355CRITICAL9.8A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.11...
CVE-2025-27129CRITICAL9.8An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ...
CVE-2025-24322CRITICAL9.8An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5....
CVE-2025-54726CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A...
CVE-2025-54713CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom...
CVE-2025-54049CRITICAL9.9Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati...
CVE-2025-54048CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom ...
CVE-2025-54014CRITICAL9.8Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Obj...
CVE-2025-53580CRITICAL9.8Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro...
CVE-2025-53577CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Cod...
CVE-2025-53299CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer ...
CVE-2025-53213CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Cond...
CVE-2025-49890CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This i...
CVE-2025-49434CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue af...
CVE-2025-49422CRITICAL9.8Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.T...
CVE-2025-49410CRITICAL10Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testi...
CVE-2025-49409CRITICAL9.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now