2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-7119CRITICAL9.8A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this...
CVE-2025-41672CRITICAL10A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool a...
CVE-2025-48501CRITICAL9.8An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an...
CVE-2025-7102CRITICAL9.8A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown...
CVE-2025-7101CRITICAL9.8A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of ...
CVE-2025-7100CRITICAL9.8A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown fu...
CVE-2025-5333CRITICAL9.5Remote attackers can execute arbitrary code in the context of the vulnerable service process.
CVE-2025-26850CRITICAL9.3The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows p...
CVE-2025-48952CRITICAL9.4NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentic...
CVE-2025-53484CRITICAL9.8User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPag...
CVE-2025-52833CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS l...
CVE-2025-52832CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart I...
CVE-2025-52831CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video...
CVE-2025-52830CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Uni...
CVE-2025-49867CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2025-49417CRITICAL9.8Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiact...
CVE-2025-49414CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Maliciou...
CVE-2025-49302CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows...
CVE-2025-47479CRITICAL9.8Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This iss...
CVE-2025-30933CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a...
CVE-2025-28983CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli...
CVE-2025-23970CRITICAL9.8Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation....
CVE-2025-28951CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow...
CVE-2025-53599CRITICAL9.8Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java...
CVE-2025-34089CRITICAL9.3An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now