2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4784CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella ...
CVE-2025-5243CRITICAL10Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS ...
CVE-2025-4822CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar En...
CVE-2025-6441CRITICAL9.8The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin ...
CVE-2025-6380CRITICAL9.8The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o...
CVE-2025-7852CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima...
CVE-2025-7437CRITICAL9.8The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ...
CVE-2025-41240CRITICAL10Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit...
CVE-2025-40599CRITICAL9.1An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att...
CVE-2025-54294CRITICAL9.3A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to e...
CVE-2025-41687CRITICAL9.8An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces...
CVE-2025-8070CRITICAL9.2The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow...
CVE-2025-54455CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54454CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54453CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54452CRITICAL9.8Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ...
CVE-2025-54451CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows...
CVE-2025-54450CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54449CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54448CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54447CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54446CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54445CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser...
CVE-2025-54444CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54443CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now