2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52816CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52725CRITICAL9.8Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects ...
CVE-2025-52724CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects A...
CVE-2025-52722CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera...
CVE-2025-52717CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett Lifte...
CVE-2025-49885CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - Wo...
CVE-2025-39474CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely am...
CVE-2025-28970CRITICAL9.8Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object ...
CVE-2025-23967CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T...
CVE-2025-6688CRITICAL9.8The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t...
CVE-2025-5306CRITICAL9.8Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af...
CVE-2025-3699CRITICAL9.8Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W ...
CVE-2025-49603CRITICAL9.1Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
CVE-2025-30131CRITICAL9.8An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execut...
CVE-2025-34049CRITICAL9.4An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112...
CVE-2025-34046CRITICAL10An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera...
CVE-2025-34044CRITICAL9.4A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router ...
CVE-2025-34043CRITICAL10A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu...
CVE-2025-34042CRITICAL9.4An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via ...
CVE-2025-53002CRITICAL9.8LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa...
CVE-2025-29331CRITICAL9.8An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme...
CVE-2025-49003CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m...
CVE-2025-6561CRITICAL9.8Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne...
CVE-2025-4334CRITICAL9.8The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2025-6668CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This aff...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now