2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52816 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52725 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects ... |
| CVE-2025-52724 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects A... |
| CVE-2025-52722 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera... |
| CVE-2025-52717 | CRITICAL | 9.8 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett Lifte... |
| CVE-2025-49885 | CRITICAL | 10 | 0.3% | Jun 27, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - Wo... |
| CVE-2025-39474 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely am... |
| CVE-2025-28970 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object ... |
| CVE-2025-23967 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T... |
| CVE-2025-6688 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t... |
| CVE-2025-5306 | CRITICAL | 9.8 | 19.9% | Jun 27, 2025 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af... |
| CVE-2025-3699 | CRITICAL | 9.8 | 1.1% | Jun 26, 2025 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W ... |
| CVE-2025-49603 | CRITICAL | 9.1 | 0.3% | Jun 26, 2025 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. |
| CVE-2025-30131 | CRITICAL | 9.8 | 0.6% | Jun 26, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execut... |
| CVE-2025-34049 | CRITICAL | 9.4 | 2.5% | Jun 26, 2025 | An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112... |
| CVE-2025-34046 | CRITICAL | 10 | 0.8% | Jun 26, 2025 | An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera... |
| CVE-2025-34044 | CRITICAL | 9.4 | 4.6% | Jun 26, 2025 | A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router ... |
| CVE-2025-34043 | CRITICAL | 10 | 9.0% | Jun 26, 2025 | A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu... |
| CVE-2025-34042 | CRITICAL | 9.4 | 1.8% | Jun 26, 2025 | An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via ... |
| CVE-2025-53002 | CRITICAL | 9.8 | 1.0% | Jun 26, 2025 | LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa... |
| CVE-2025-29331 | CRITICAL | 9.8 | 0.4% | Jun 26, 2025 | An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme... |
| CVE-2025-49003 | CRITICAL | 9.8 | 0.8% | Jun 26, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m... |
| CVE-2025-6561 | CRITICAL | 9.8 | 0.5% | Jun 26, 2025 | Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne... |
| CVE-2025-4334 | CRITICAL | 9.8 | 2.1% | Jun 26, 2025 | The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu... |
| CVE-2025-6668 | CRITICAL | 9.8 | 0.4% | Jun 25, 2025 | A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This aff... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now