2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-39503CRITICAL9.8Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This i...
CVE-2025-39501CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay...
CVE-2025-39500CRITICAL9.8Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This...
CVE-2025-39499CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affec...
CVE-2025-39495CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affec...
CVE-2025-39494CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39489CRITICAL9.8Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects C...
CVE-2025-39485CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue af...
CVE-2025-39480CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue a...
CVE-2025-32292CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis ...
CVE-2025-31927CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:...
CVE-2025-31918CRITICAL9.8Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro...
CVE-2025-31916CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium ...
CVE-2025-31914CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel...
CVE-2025-31631CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue...
CVE-2025-31430CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The...
CVE-2025-31423CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec...
CVE-2025-31397CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke...
CVE-2025-31069CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti...
CVE-2025-31056CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar...
CVE-2025-31049CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ...
CVE-2025-3895CRITICAL9.1Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ...
CVE-2025-5099CRITICAL9.8An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c...
CVE-2025-5098CRITICAL9.1PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's...
CVE-2025-48373CRITICAL9.1Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now