2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-46199CRITICAL9.8Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafte...
CVE-2025-29631CRITICAL9.8Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1...
CVE-2025-29629CRITICAL9.1Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1...
CVE-2025-29628CRITICAL9.4A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware befo...
CVE-2025-8159CRITICAL9.8A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLang...
CVE-2025-45777CRITICAL9.8An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass au...
CVE-2025-8125CRITICAL9.8A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some...
CVE-2025-54379CRITICAL9.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2025-54369CRITICAL9.3Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo...
CVE-2025-32429CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4...
CVE-2025-7404CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,...
CVE-2025-6260CRITICAL9.8The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta...
CVE-2025-48732CRITICAL9.8An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c...
CVE-2025-41420CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4...
CVE-2025-36548CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of W...
CVE-2025-4784CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella ...
CVE-2025-5243CRITICAL10Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS ...
CVE-2025-4822CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar En...
CVE-2025-6441CRITICAL9.8The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin ...
CVE-2025-6380CRITICAL9.8The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o...
CVE-2025-7852CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima...
CVE-2025-7437CRITICAL9.8The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ...
CVE-2025-41240CRITICAL10Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit...
CVE-2025-40599CRITICAL9.1An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att...
CVE-2025-54294CRITICAL9.3A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now