2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-56590CRITICAL9.8An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ...
CVE-2025-69828CRITICAL10File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ...
CVE-2025-69312CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows...
CVE-2025-69101CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows ...
CVE-2025-69079CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O...
CVE-2025-69052CRITICAL9.8Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registrat...
CVE-2025-68986CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W...
CVE-2025-68910CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File...
CVE-2025-68909CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ...
CVE-2025-68869CRITICAL9.8Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil...
CVE-2025-68857CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow...
CVE-2025-68034CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve...
CVE-2025-68018CRITICAL9.4Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec...
CVE-2025-68015CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner e...
CVE-2025-68001CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a ...
CVE-2025-67968CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using...
CVE-2025-67945CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL...
CVE-2025-67944CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test...
CVE-2025-67617CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af...
CVE-2025-62056CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne...
CVE-2025-62050CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blog...
CVE-2025-50002CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a W...
CVE-2025-49055CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le...
CVE-2025-69764CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl...
CVE-2025-64097CRITICAL9.8NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now