2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-39395CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apa...
CVE-2025-39389CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins Anal...
CVE-2025-39386CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ...
CVE-2025-39380CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management...
CVE-2025-39356CRITICAL9.8Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Obje...
CVE-2025-39354CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.T...
CVE-2025-39349CRITICAL9.8Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop ciyashop allows Object Injection.This...
CVE-2025-39348CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T...
CVE-2025-32928CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects A...
CVE-2025-32927CRITICAL9.8Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This iss...
CVE-2025-32926CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaur...
CVE-2025-32925CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47581CRITICAL9.8Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplu...
CVE-2025-47577CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce...
CVE-2025-47284CRITICAL9.9Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability...
CVE-2025-47283CRITICAL9.9Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability...
CVE-2025-39445CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2025-39410CRITICAL9.8Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon...
CVE-2025-39406CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47582CRITICAL9.8Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This...
CVE-2025-47282CRITICAL9.9Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security v...
CVE-2025-26892CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.Thi...
CVE-2025-26872CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue...
CVE-2025-4941CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0...
CVE-2025-4938CRITICAL9.8A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now