2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-28959CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haide...
CVE-2025-24759CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPr...
CVE-2025-54010CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Re...
CVE-2025-7673CRITICAL9.8A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior...
CVE-2025-52689CRITICAL9.8Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a...
CVE-2025-52688CRITICAL9.8Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce...
CVE-2025-49841CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49840CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49839CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49838CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49837CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49836CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49835CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49834CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49833CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49831CRITICAL9.8An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misco...
CVE-2025-50067CRITICAL9Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are aff...
CVE-2025-49827CRITICAL9.8Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22....
CVE-2025-41238CRITICAL9.3VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controll...
CVE-2025-41237CRITICAL9.3VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that...
CVE-2025-41236CRITICAL9.3VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A...
CVE-2025-53826CRITICAL9.8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52376CRITICAL9.8An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ...
CVE-2025-34112CRITICAL10An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr...
CVE-2025-34111CRITICAL9.8An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now