2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49295CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This is...
CVE-2025-48281CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform My...
CVE-2025-48267CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allow...
CVE-2025-48141CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Mult...
CVE-2025-48140CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi all...
CVE-2025-48129CRITICAL9.8Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-co...
CVE-2025-48126CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48123CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer ...
CVE-2025-48122CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering...
CVE-2025-47608CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recov...
CVE-2025-32291CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using ...
CVE-2025-31429CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme all...
CVE-2025-31424CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le...
CVE-2025-31398CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This i...
CVE-2025-31396CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. Thi...
CVE-2025-31059CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in woobewoo WBW Produ...
CVE-2025-31052CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion ...
CVE-2025-31039CRITICAL9.1Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML...
CVE-2025-31022CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authen...
CVE-2025-24767CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketB...
CVE-2025-5881CRITICAL9.8A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unk...
CVE-2025-49131CRITICAL9.9FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows an...
CVE-2025-49013CRITICAL9.9WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across th...
CVE-2025-48877CRITICAL9.8Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t...
CVE-2025-3835CRITICAL9.6Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Cont...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now