2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-50201CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id...
CVE-2025-52467CRITICAL9.1pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c...
CVE-2025-24288CRITICAL9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default ...
CVE-2025-49591CRITICAL9.1CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad...
CVE-2025-26199CRITICAL9.8CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm...
CVE-2025-26198CRITICAL9.8CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The...
CVE-2025-20260CRITICAL9.8A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe...
CVE-2025-46157CRITICAL9.9An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function...
CVE-2025-45784CRITICAL9.8D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may...
CVE-2025-1562CRITICAL9.8The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word...
CVE-2025-51381CRITICAL9.8An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at...
CVE-2025-49825CRITICAL9.8Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions...
CVE-2025-49217CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49216CRITICAL9.8An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to ac...
CVE-2025-49213CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49212CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49220CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat...
CVE-2025-49219CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica...
CVE-2025-47867CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta...
CVE-2025-47865CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker...
CVE-2025-49452CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Ladó PostaP...
CVE-2025-49447CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files....
CVE-2025-49444CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor all...
CVE-2025-49330CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho...
CVE-2025-49071CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now