2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-63624CRITICAL9.8SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows...
CVE-2025-61506CRITICAL9.8An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ...
CVE-2025-57529CRITICAL9.8YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to...
CVE-2025-52626CRITICAL9.8A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially ...
CVE-2025-5319CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics a...
CVE-2025-67856CRITICAL9.8A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awa...
CVE-2025-67484CRITICAL9.8Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFor...
CVE-2025-66480CRITICAL9.8Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists ...
CVE-2025-8587CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech...
CVE-2025-15030CRITICAL9.8The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u...
CVE-2025-24293CRITICAL9.2# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote...
CVE-2025-51958CRITICAL9.8aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com...
CVE-2025-7964CRITICAL9.2After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb...
CVE-2025-26385CRITICAL9.5Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com...
CVE-2025-69929CRITICAL9.8An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw...
CVE-2025-7714CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive...
CVE-2025-7013CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo...
CVE-2025-7016CRITICAL9.8Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut...
CVE-2025-7015CRITICAL9.8Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi...
CVE-2025-68662CRITICAL9.9Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn...
CVE-2025-69602CRITICAL9.1A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th...
CVE-2025-57795CRITICAL9.9Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c...
CVE-2025-57794CRITICAL9.1Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ...
CVE-2025-57792CRITICAL10Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user...
CVE-2025-61140CRITICAL9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now