2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-51381CRITICAL9.8An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at...
CVE-2025-49825CRITICAL9.8Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions...
CVE-2025-49217CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49216CRITICAL9.8An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to ac...
CVE-2025-49213CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49212CRITICAL9.8An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentica...
CVE-2025-49220CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authenticat...
CVE-2025-49219CRITICAL9.8An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentica...
CVE-2025-47867CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an atta...
CVE-2025-47865CRITICAL9.8A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker...
CVE-2025-49452CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Ladó PostaP...
CVE-2025-49447CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files....
CVE-2025-49444CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor all...
CVE-2025-49330CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho...
CVE-2025-49071CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell...
CVE-2025-47573CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Ma...
CVE-2025-47559CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg allows Upload a Web Shell to a ...
CVE-2025-47452CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web ...
CVE-2025-39479CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart ...
CVE-2025-32510CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager all...
CVE-2025-31919CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: fro...
CVE-2025-30618CRITICAL9.8Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows ...
CVE-2025-24773CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPCRM - C...
CVE-2025-4404CRITICAL9.1A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to ...
CVE-2025-3515CRITICAL9.8The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now