2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-6776CRITICAL9.8A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects...
CVE-2025-6775CRITICAL9.8A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the func...
CVE-2025-5310CRITICAL9.8Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication fra...
CVE-2025-52207CRITICAL9.9PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit...
CVE-2025-53091CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Bl...
CVE-2025-52553CRITICAL9.6authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token whi...
CVE-2025-53314CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affe...
CVE-2025-53260CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file...
CVE-2025-52834CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey h...
CVE-2025-52829CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ ...
CVE-2025-52816CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52725CRITICAL9.8Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects ...
CVE-2025-52724CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects A...
CVE-2025-52722CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera...
CVE-2025-52717CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett Lifte...
CVE-2025-49885CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - Wo...
CVE-2025-39474CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely am...
CVE-2025-28970CRITICAL9.8Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object ...
CVE-2025-23967CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T...
CVE-2025-6688CRITICAL9.8The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t...
CVE-2025-5306CRITICAL9.8Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af...
CVE-2025-3699CRITICAL9.8Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W ...
CVE-2025-49603CRITICAL9.1Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
CVE-2025-30131CRITICAL9.8An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execut...
CVE-2025-34049CRITICAL9.4An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now