2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-37107CRITICAL9.8An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37106CRITICAL9.8An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior ...
CVE-2025-37105CRITICAL9.8An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-20337CRITICAL10A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec...
CVE-2025-53937CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection...
CVE-2025-34300CRITICAL10A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ci...
CVE-2025-52836CRITICAL9.8Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr...
CVE-2025-52714CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-48300CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web ...
CVE-2025-30973CRITICAL9.8Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This iss...
CVE-2025-30949CRITICAL9.8Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object I...
CVE-2025-30936CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for ...
CVE-2025-29009CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCo...
CVE-2025-28982CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes...
CVE-2025-28961CRITICAL9.8Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection...
CVE-2025-28959CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haide...
CVE-2025-24759CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPr...
CVE-2025-54010CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Re...
CVE-2025-7673CRITICAL9.8A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior...
CVE-2025-52689CRITICAL9.8Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a...
CVE-2025-52688CRITICAL9.8Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce...
CVE-2025-49841CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49840CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49839CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49838CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now