2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52833 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS l... |
| CVE-2025-52832 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart I... |
| CVE-2025-52831 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video... |
| CVE-2025-52830 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Uni... |
| CVE-2025-49867 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue... |
| CVE-2025-49417 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiact... |
| CVE-2025-49414 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Maliciou... |
| CVE-2025-49302 | CRITICAL | 10 | 0.4% | Jul 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows... |
| CVE-2025-47479 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This iss... |
| CVE-2025-30933 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a... |
| CVE-2025-28983 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli... |
| CVE-2025-23970 | CRITICAL | 9.8 | 0.7% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.... |
| CVE-2025-28951 | CRITICAL | 9.1 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow... |
| CVE-2025-53599 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java... |
| CVE-2025-34089 | CRITICAL | 9.3 | 1.4% | Jul 3, 2025 | An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope... |
| CVE-2025-34082 | CRITICAL | 9.3 | 5.3% | Jul 3, 2025 | A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh... |
| CVE-2025-34061 | CRITICAL | 9.3 | 1.2% | Jul 3, 2025 | A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ... |
| CVE-2025-23968 | CRITICAL | 9.1 | 0.4% | Jul 3, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Uploa... |
| CVE-2025-27456 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp... |
| CVE-2025-27449 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh... |
| CVE-2025-1710 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi... |
| CVE-2025-34074 | CRITICAL | 9.4 | 1.1% | Jul 2, 2025 | An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i... |
| CVE-2025-45813 | CRITICAL | 9.8 | 0.4% | Jul 2, 2025 | ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. |
| CVE-2025-45814 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v... |
| CVE-2025-20309 | CRITICAL | 10 | 1.1% | Jul 2, 2025 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now