2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-70983CRITICAL9.9Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-67229CRITICAL9.8An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth...
CVE-2025-66719CRITICAL9.1An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck...
CVE-2025-4320CRITICAL10Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire...
CVE-2025-4319CRITICAL9.4Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne...
CVE-2025-15063CRITICAL9.8Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta...
CVE-2025-15061CRITICAL9.8Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-55705CRITICAL9.8This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg...
CVE-2025-54816CRITICAL9.8This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho...
CVE-2025-56590CRITICAL9.8An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ...
CVE-2025-69828CRITICAL10File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ...
CVE-2025-69312CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows...
CVE-2025-69101CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows ...
CVE-2025-69079CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O...
CVE-2025-69052CRITICAL9.8Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registrat...
CVE-2025-68986CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W...
CVE-2025-68910CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File...
CVE-2025-68909CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ...
CVE-2025-68869CRITICAL9.8Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil...
CVE-2025-68857CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow...
CVE-2025-68034CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve...
CVE-2025-68018CRITICAL9.4Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec...
CVE-2025-68015CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner e...
CVE-2025-68001CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a ...
CVE-2025-67968CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now