2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49507CRITICAL9.8Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect...
CVE-2025-49455CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor...
CVE-2025-43698CRITICAL9.1Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec...
CVE-2025-40657CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40656CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40655CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40654CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-1041CRITICAL9.8An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v...
CVE-2025-5913CRITICAL9.8A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue ...
CVE-2025-5906CRITICAL9.8A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part ...
CVE-2025-42989CRITICAL9.6RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio...
CVE-2025-30184CRITICAL9.8CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
CVE-2025-49652CRITICAL9.8Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ...
CVE-2025-49297CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T...
CVE-2025-49296CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu...
CVE-2025-49295CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This is...
CVE-2025-48281CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform My...
CVE-2025-48267CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allow...
CVE-2025-48141CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Mult...
CVE-2025-48140CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi all...
CVE-2025-48129CRITICAL9.8Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-co...
CVE-2025-48126CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48123CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer ...
CVE-2025-48122CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering...
CVE-2025-47608CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recov...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now