2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1242CRITICAL9.3The administrative credentials can be extracted through application API responses, mobile application reverse engineerin...
CVE-2025-62878CRITICAL9.9A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos...
CVE-2025-69985CRITICAL9.8FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera...
CVE-2025-14577CRITICAL9.8Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e...
CVE-2025-11165CRITICAL9.9A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit...
CVE-2025-13942CRITICAL9.8A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C...
CVE-2025-70327CRITICAL9.8TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of t...
CVE-2025-70043CRITICAL9.1An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d...
CVE-2025-41002CRITICAL9.3SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create...
CVE-2025-70833CRITICAL9.4An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u...
CVE-2025-70831CRITICAL9.8A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica...
CVE-2025-69405CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st...
CVE-2025-69404CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu...
CVE-2025-69403CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using ...
CVE-2025-69382CRITICAL9.8Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object In...
CVE-2025-69372CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue...
CVE-2025-69371CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue...
CVE-2025-69370CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects...
CVE-2025-69366CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerc...
CVE-2025-69365CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan...
CVE-2025-69337CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart...
CVE-2025-69329CRITICAL9.8Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects ...
CVE-2025-69310CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodl...
CVE-2025-69309CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasp...
CVE-2025-69308CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestb...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now