2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12462CRITICAL9.3A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to injec...
CVE-2025-30044CRITICAL9.4In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-...
CVE-2025-30035CRITICAL9The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ...
CVE-2025-15498CRITICAL9.3Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ...
CVE-2025-11252CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ...
CVE-2025-11251CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I...
CVE-2025-12981CRITICAL9.8The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i...
CVE-2025-50857CRITICAL9.8ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker...
CVE-2025-69771CRITICAL9.6Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14...
CVE-2025-1242CRITICAL9.3The administrative credentials can be extracted through application API responses, mobile application reverse engineerin...
CVE-2025-62878CRITICAL9.9A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos...
CVE-2025-69985CRITICAL9.8FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera...
CVE-2025-14577CRITICAL9.8Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e...
CVE-2025-11165CRITICAL9.9A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit...
CVE-2025-13942CRITICAL9.8A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C...
CVE-2025-70327CRITICAL9.8TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of t...
CVE-2025-70043CRITICAL9.1An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d...
CVE-2025-41002CRITICAL9.3SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create...
CVE-2025-70833CRITICAL9.4An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u...
CVE-2025-70831CRITICAL9.8A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica...
CVE-2025-69405CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st...
CVE-2025-69404CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu...
CVE-2025-69403CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using ...
CVE-2025-69382CRITICAL9.8Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object In...
CVE-2025-69372CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now