2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12462 | CRITICAL | 9.3 | 0.4% | Mar 2, 2026 | A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to injec... |
| CVE-2025-30044 | CRITICAL | 9.4 | 0.5% | Mar 2, 2026 | In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-... |
| CVE-2025-30035 | CRITICAL | 9 | 0.2% | Mar 2, 2026 | The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ... |
| CVE-2025-15498 | CRITICAL | 9.3 | 0.5% | Feb 27, 2026 | Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ... |
| CVE-2025-11252 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ... |
| CVE-2025-11251 | CRITICAL | 9.8 | 0.4% | Feb 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I... |
| CVE-2025-12981 | CRITICAL | 9.8 | 0.6% | Feb 27, 2026 | The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i... |
| CVE-2025-50857 | CRITICAL | 9.8 | 2.3% | Feb 26, 2026 | ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attacker... |
| CVE-2025-69771 | CRITICAL | 9.6 | 0.3% | Feb 25, 2026 | Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14... |
| CVE-2025-1242 | CRITICAL | 9.3 | 0.4% | Feb 25, 2026 | The administrative credentials can be extracted through application API responses, mobile application reverse engineerin... |
| CVE-2025-62878 | CRITICAL | 9.9 | 0.6% | Feb 25, 2026 | A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos... |
| CVE-2025-69985 | CRITICAL | 9.8 | 5.6% | Feb 24, 2026 | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera... |
| CVE-2025-14577 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e... |
| CVE-2025-11165 | CRITICAL | 9.9 | 0.3% | Feb 24, 2026 | A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit... |
| CVE-2025-13942 | CRITICAL | 9.8 | 1.1% | Feb 24, 2026 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C... |
| CVE-2025-70327 | CRITICAL | 9.8 | 0.7% | Feb 23, 2026 | TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of t... |
| CVE-2025-70043 | CRITICAL | 9.1 | 0.2% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d... |
| CVE-2025-41002 | CRITICAL | 9.3 | 0.3% | Feb 23, 2026 | SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create... |
| CVE-2025-70833 | CRITICAL | 9.4 | 0.4% | Feb 20, 2026 | An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u... |
| CVE-2025-70831 | CRITICAL | 9.8 | 0.9% | Feb 20, 2026 | A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica... |
| CVE-2025-69405 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st... |
| CVE-2025-69404 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu... |
| CVE-2025-69403 | CRITICAL | 9.9 | 0.4% | Feb 20, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using ... |
| CVE-2025-69382 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object In... |
| CVE-2025-69372 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now