2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25257CRITICAL9.8An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi...
CVE-2025-53928CRITICAL9.8MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ...
CVE-2025-51630CRITICAL9.8TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi...
CVE-2025-7712CRITICAL9.1The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...
CVE-2025-5396CRITICAL9.8The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0...
CVE-2025-34132CRITICAL9.3A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...
CVE-2025-34127CRITICAL9.3A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag...
CVE-2025-34125CRITICAL9.3An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D...
CVE-2025-34121CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc...
CVE-2025-34117CRITICAL9.3A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t...
CVE-2025-37107CRITICAL9.8An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37106CRITICAL9.8An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior ...
CVE-2025-37105CRITICAL9.8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-20337CRITICAL10A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec...
CVE-2025-53937CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-34300CRITICAL10A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ci...
CVE-2025-52836CRITICAL9.8Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr...
CVE-2025-52714CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-48300CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web ...
CVE-2025-30973CRITICAL9.8Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This iss...
CVE-2025-30949CRITICAL9.8Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object I...
CVE-2025-30936CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for ...
CVE-2025-29009CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCo...
CVE-2025-28982CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes...
CVE-2025-28961CRITICAL9.8Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now