2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56590 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ... |
| CVE-2025-69828 | CRITICAL | 10 | 0.5% | Jan 22, 2026 | File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ... |
| CVE-2025-69312 | CRITICAL | 9.1 | 0.3% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows... |
| CVE-2025-69101 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows ... |
| CVE-2025-69079 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O... |
| CVE-2025-69052 | CRITICAL | 9.8 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registrat... |
| CVE-2025-68986 | CRITICAL | 9.9 | 0.4% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W... |
| CVE-2025-68910 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File... |
| CVE-2025-68909 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ... |
| CVE-2025-68869 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil... |
| CVE-2025-68857 | CRITICAL | 9.3 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow... |
| CVE-2025-68034 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve... |
| CVE-2025-68018 | CRITICAL | 9.4 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec... |
| CVE-2025-68015 | CRITICAL | 9 | 0.3% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner e... |
| CVE-2025-68001 | CRITICAL | 10 | 0.6% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a ... |
| CVE-2025-67968 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using... |
| CVE-2025-67945 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL... |
| CVE-2025-67944 | CRITICAL | 9.1 | 0.5% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test... |
| CVE-2025-67617 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af... |
| CVE-2025-62056 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne... |
| CVE-2025-62050 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blog... |
| CVE-2025-50002 | CRITICAL | 10 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a W... |
| CVE-2025-49055 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le... |
| CVE-2025-69764 | CRITICAL | 9.8 | 1.0% | Jan 22, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-64097 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now