2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-67945CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL...
CVE-2025-67944CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test...
CVE-2025-67617CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af...
CVE-2025-62056CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne...
CVE-2025-62050CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blog...
CVE-2025-50002CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a W...
CVE-2025-49055CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le...
CVE-2025-69764CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl...
CVE-2025-64097CRITICAL9.8NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu...
CVE-2025-27378CRITICAL9.8AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f...
CVE-2025-69766CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl...
CVE-2025-69763CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor...
CVE-2025-69762CRITICAL9.8Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ...
CVE-2025-15521CRITICAL9.8The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e...
CVE-2025-55130CRITICAL9.1A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u...
CVE-2025-56005CRITICAL9.8An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ...
CVE-2025-55423CRITICAL9.8A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr...
CVE-2025-65482CRITICAL9.8An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra...
CVE-2025-64087CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2....
CVE-2025-36418CRITICAL9.8IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A...
CVE-2025-14533CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a...
CVE-2025-55252CRITICAL9.8HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable pas...
CVE-2025-55251CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-52660CRITICAL9.8HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re...
CVE-2025-11043CRITICAL9.1An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now