2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49507 | CRITICAL | 9.8 | 0.5% | Jun 10, 2025 | Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect... |
| CVE-2025-49455 | CRITICAL | 9.3 | 0.4% | Jun 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor... |
| CVE-2025-43698 | CRITICAL | 9.1 | 0.4% | Jun 10, 2025 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec... |
| CVE-2025-40657 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40656 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40655 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-40654 | CRITICAL | 9.8 | 0.3% | Jun 10, 2025 | A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-1041 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v... |
| CVE-2025-5913 | CRITICAL | 9.8 | 0.4% | Jun 10, 2025 | A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue ... |
| CVE-2025-5906 | CRITICAL | 9.8 | 0.5% | Jun 10, 2025 | A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part ... |
| CVE-2025-42989 | CRITICAL | 9.6 | 0.4% | Jun 10, 2025 | RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio... |
| CVE-2025-30184 | CRITICAL | 9.8 | 0.5% | Jun 9, 2025 | CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path. |
| CVE-2025-49652 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ... |
| CVE-2025-49297 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T... |
| CVE-2025-49296 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu... |
| CVE-2025-49295 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This is... |
| CVE-2025-48281 | CRITICAL | 9.3 | 1.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform My... |
| CVE-2025-48267 | CRITICAL | 9.1 | 0.4% | Jun 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allow... |
| CVE-2025-48141 | CRITICAL | 9.3 | 0.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Mult... |
| CVE-2025-48140 | CRITICAL | 9.9 | 0.3% | Jun 9, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi all... |
| CVE-2025-48129 | CRITICAL | 9.8 | 0.5% | Jun 9, 2025 | Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-co... |
| CVE-2025-48126 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48123 | CRITICAL | 10 | 0.4% | Jun 9, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer ... |
| CVE-2025-48122 | CRITICAL | 9.3 | 0.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering... |
| CVE-2025-47608 | CRITICAL | 9.3 | 0.7% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recov... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now