2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-13851CRITICAL9.8The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re...
CVE-2025-13563CRITICAL9.8The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2025-12882CRITICAL9.8The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ...
CVE-2025-70152CRITICAL9.8code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management...
CVE-2025-70150CRITICAL9.8CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al...
CVE-2025-14009CRITICAL10A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f...
CVE-2025-70149CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame...
CVE-2025-70146CRITICAL9.1Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera...
CVE-2025-70141CRITICAL9.4SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp...
CVE-2025-70998CRITICAL9.8UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel...
CVE-2025-65791CRITICAL9.8ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i...
CVE-2025-15579CRITICAL9.5Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerabi...
CVE-2025-33089CRITICAL9.8IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac...
CVE-2025-66614CRITICAL9.1Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-...
CVE-2025-59793CRITICAL9.9Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica...
CVE-2025-70830CRITICAL9.9A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut...
CVE-2025-15578CRITICAL9.8Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys...
CVE-2025-32058CRITICAL9.3The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment...
CVE-2025-8572CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7...
CVE-2025-69633CRITICAL9.8A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ...
CVE-2025-69770CRITICAL10A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu...
CVE-2025-70314CRITICAL9.8webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable
CVE-2025-70981CRITICAL9.8CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p...
CVE-2025-69634CRITICAL9Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ...
CVE-2025-14014CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now