2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52833CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS l...
CVE-2025-52832CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart I...
CVE-2025-52831CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video...
CVE-2025-52830CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Uni...
CVE-2025-49867CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2025-49417CRITICAL9.8Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiact...
CVE-2025-49414CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Maliciou...
CVE-2025-49302CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows...
CVE-2025-47479CRITICAL9.8Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This iss...
CVE-2025-30933CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a...
CVE-2025-28983CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli...
CVE-2025-23970CRITICAL9.8Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation....
CVE-2025-28951CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow...
CVE-2025-53599CRITICAL9.8Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java...
CVE-2025-34089CRITICAL9.3An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope...
CVE-2025-34082CRITICAL9.3A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh...
CVE-2025-34061CRITICAL9.3A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ...
CVE-2025-23968CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Uploa...
CVE-2025-27456CRITICAL9.8The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp...
CVE-2025-27449CRITICAL9.8The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh...
CVE-2025-1710CRITICAL9.8The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi...
CVE-2025-34074CRITICAL9.4An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i...
CVE-2025-45813CRITICAL9.8ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
CVE-2025-45814CRITICAL9.8Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v...
CVE-2025-20309CRITICAL10A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now