2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-69307CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medin...
CVE-2025-69306CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Elect...
CVE-2025-69305CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete...
CVE-2025-69304CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allma...
CVE-2025-69301CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects...
CVE-2025-69295CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven...
CVE-2025-68549CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to...
CVE-2025-68541CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects I...
CVE-2025-67997CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss...
CVE-2025-67996CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N...
CVE-2025-67995CRITICAL9.8Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe...
CVE-2025-67979CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gs...
CVE-2025-10970CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc...
CVE-2025-30416CRITICAL10Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cy...
CVE-2025-30412CRITICAL10Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ...
CVE-2025-30411CRITICAL10Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ...
CVE-2025-30410CRITICAL9.8Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C...
CVE-2025-67305CRITICAL9.8In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ...
CVE-2025-67304CRITICAL9.8In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ...
CVE-2025-71243CRITICAL9.8The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex...
CVE-2025-55853CRITICAL9.1SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not...
CVE-2025-9953CRITICAL9.8Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd....
CVE-2025-8350CRITICAL9.8Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern...
CVE-2025-15559CRITICAL9.8An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server...
CVE-2025-15586CRITICAL10OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now