2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27129CRITICAL9.8An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ...
CVE-2025-24322CRITICAL9.8An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5....
CVE-2025-54726CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A...
CVE-2025-54713CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom...
CVE-2025-54049CRITICAL9.9Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati...
CVE-2025-54048CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom ...
CVE-2025-54014CRITICAL9.8Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Obj...
CVE-2025-53580CRITICAL9.8Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro...
CVE-2025-53577CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Cod...
CVE-2025-53299CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer ...
CVE-2025-53213CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Cond...
CVE-2025-49890CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This i...
CVE-2025-49434CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue af...
CVE-2025-49422CRITICAL9.8Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.T...
CVE-2025-49410CRITICAL10Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testi...
CVE-2025-49409CRITICAL9.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPre...
CVE-2025-49408CRITICAL10Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi...
CVE-2025-49400CRITICAL9.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit...
CVE-2025-49381CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Si...
CVE-2025-48169CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Rem...
CVE-2025-48148CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe...
CVE-2025-9187CRITICAL9.8Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a...
CVE-2025-9179CRITICAL9.8An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al...
CVE-2025-8042CRITICAL9.8Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab...
CVE-2025-55031CRITICAL9.8Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now