2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6776 | CRITICAL | 9.8 | 0.6% | Jun 27, 2025 | A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects... |
| CVE-2025-6775 | CRITICAL | 9.8 | 3.5% | Jun 27, 2025 | A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the func... |
| CVE-2025-5310 | CRITICAL | 9.8 | 0.7% | Jun 27, 2025 | Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication fra... |
| CVE-2025-52207 | CRITICAL | 9.9 | 1.5% | Jun 27, 2025 | PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit... |
| CVE-2025-53091 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Bl... |
| CVE-2025-52553 | CRITICAL | 9.6 | 0.4% | Jun 27, 2025 | authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token whi... |
| CVE-2025-53314 | CRITICAL | 9.6 | 0.1% | Jun 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affe... |
| CVE-2025-53260 | CRITICAL | 9.1 | 0.3% | Jun 27, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file... |
| CVE-2025-52834 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey h... |
| CVE-2025-52829 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ ... |
| CVE-2025-52816 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52725 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects ... |
| CVE-2025-52724 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects A... |
| CVE-2025-52722 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera... |
| CVE-2025-52717 | CRITICAL | 9.8 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett Lifte... |
| CVE-2025-49885 | CRITICAL | 10 | 0.3% | Jun 27, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - Wo... |
| CVE-2025-39474 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely am... |
| CVE-2025-28970 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object ... |
| CVE-2025-23967 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T... |
| CVE-2025-6688 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t... |
| CVE-2025-5306 | CRITICAL | 9.8 | 19.9% | Jun 27, 2025 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af... |
| CVE-2025-3699 | CRITICAL | 9.8 | 1.1% | Jun 26, 2025 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W ... |
| CVE-2025-49603 | CRITICAL | 9.1 | 0.3% | Jun 26, 2025 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. |
| CVE-2025-30131 | CRITICAL | 9.8 | 0.6% | Jun 26, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execut... |
| CVE-2025-34049 | CRITICAL | 9.4 | 2.5% | Jun 26, 2025 | An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now