2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69307 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medin... |
| CVE-2025-69306 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Elect... |
| CVE-2025-69305 | CRITICAL | 9.3 | 0.4% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete... |
| CVE-2025-69304 | CRITICAL | 9.3 | 0.4% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allma... |
| CVE-2025-69301 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects... |
| CVE-2025-69295 | CRITICAL | 9.3 | 0.4% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven... |
| CVE-2025-68549 | CRITICAL | 9.9 | 0.4% | Feb 20, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to... |
| CVE-2025-68541 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects I... |
| CVE-2025-67997 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss... |
| CVE-2025-67996 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N... |
| CVE-2025-67995 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe... |
| CVE-2025-67979 | CRITICAL | 9.9 | 0.4% | Feb 20, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gs... |
| CVE-2025-10970 | CRITICAL | 9.8 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc... |
| CVE-2025-30416 | CRITICAL | 10 | 0.4% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cy... |
| CVE-2025-30412 | CRITICAL | 10 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ... |
| CVE-2025-30411 | CRITICAL | 10 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ... |
| CVE-2025-30410 | CRITICAL | 9.8 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C... |
| CVE-2025-67305 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ... |
| CVE-2025-67304 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ... |
| CVE-2025-71243 | CRITICAL | 9.8 | 5.1% | Feb 19, 2026 | The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex... |
| CVE-2025-55853 | CRITICAL | 9.1 | 0.4% | Feb 19, 2026 | SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not... |
| CVE-2025-9953 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd.... |
| CVE-2025-8350 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern... |
| CVE-2025-15559 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server... |
| CVE-2025-15586 | CRITICAL | 10 | 0.4% | Feb 19, 2026 | OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now