2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-46828CRITICAL9.8WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in ve...
CVE-2025-20221CRITICAL9.1A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote ...
CVE-2025-20188CRITICAL10A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de...
CVE-2025-47688CRITICAL9.8Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrec...
CVE-2025-47657CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds P...
CVE-2025-47635CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Server Side Req...
CVE-2025-47548CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress act...
CVE-2025-2777CRITICAL9.8SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the l...
CVE-2025-2776CRITICAL9.8SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S...
CVE-2025-4104CRITICAL9.8The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t...
CVE-2025-20968CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...
CVE-2025-20967CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...
CVE-2025-20949CRITICAL9.1Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary ...
CVE-2025-0668CRITICAL9.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve...
CVE-2025-32404CRITICAL9.8An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ...
CVE-2025-32403CRITICAL9.8An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ...
CVE-2025-32401CRITICAL9.8An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d...
CVE-2025-3844CRITICAL9.8The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to...
CVE-2025-0855CRITICAL9.8The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ...
CVE-2025-47419CRITICAL10Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ...
CVE-2025-46572CRITICAL9.3passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ...
CVE-2025-44899CRITICAL9.8There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we...
CVE-2025-44073CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-46816CRITICAL9.4goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a...
CVE-2025-25014CRITICAL9.8A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now