2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49408CRITICAL10Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi...
CVE-2025-49400CRITICAL9.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit...
CVE-2025-49381CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Si...
CVE-2025-48169CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Rem...
CVE-2025-48148CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe...
CVE-2025-9187CRITICAL9.8Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a...
CVE-2025-9179CRITICAL9.8An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al...
CVE-2025-8042CRITICAL9.8Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab...
CVE-2025-55031CRITICAL9.8Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att...
CVE-2025-54145CRITICAL9.1The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev...
CVE-2025-54143CRITICAL9.8Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio...
CVE-2025-9156CRITICAL9.8A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t...
CVE-2025-9155CRITICAL9.8A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func...
CVE-2025-51543CRITICAL9.8An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini...
CVE-2025-9154CRITICAL9.8A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc...
CVE-2025-55733CRITICAL9.6DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r...
CVE-2025-55306CRITICAL9.8GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F...
CVE-2025-9149CRITICAL9.8A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg...
CVE-2025-55294CRITICAL9.8screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue....
CVE-2025-54336CRITICAL9.8In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b...
CVE-2025-50567CRITICAL10Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac...
CVE-2025-8723CRITICAL9.8The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ...
CVE-2025-6758CRITICAL9.8The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the...
CVE-2025-55591CRITICAL9.8TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac param...
CVE-2025-55213CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now