2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-15030CRITICAL9.8The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u...
CVE-2025-24293CRITICAL9.2# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote...
CVE-2025-51958CRITICAL9.8aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com...
CVE-2025-7964CRITICAL9.2After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb...
CVE-2025-26385CRITICAL9.5Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com...
CVE-2025-69929CRITICAL9.8An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw...
CVE-2025-7714CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive...
CVE-2025-7013CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo...
CVE-2025-7016CRITICAL9.8Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut...
CVE-2025-7015CRITICAL9.8Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi...
CVE-2025-68662CRITICAL9.9Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn...
CVE-2025-69602CRITICAL9.1A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th...
CVE-2025-57795CRITICAL9.9Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c...
CVE-2025-57794CRITICAL9.1Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ...
CVE-2025-57792CRITICAL10Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user...
CVE-2025-61140CRITICAL9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2025-40554CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could...
CVE-2025-40553CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40552CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ...
CVE-2025-40551CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40536CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could...
CVE-2025-21589CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a...
CVE-2025-14988CRITICAL10A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co...
CVE-2025-69564CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres...
CVE-2025-69563CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now