2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-3800CRITICAL9.8A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown funct...
CVE-2025-3799CRITICAL9.8A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app...
CVE-2025-1093CRITICAL9.8The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat...
CVE-2025-3278CRITICAL9.8The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0....
CVE-2025-29058CRITICAL9.8An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-28197CRITICAL9.1Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
CVE-2025-28242CRITICAL9.8Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session ...
CVE-2025-28238CRITICAL9.8Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers t...
CVE-2025-28236CRITICAL9.8Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerabili...
CVE-2025-28233CRITICAL9.1Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Ve...
CVE-2025-28231CRITICAL9.1Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary comma...
CVE-2025-32434CRITICAL9.8PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built...
CVE-2025-29953CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache Activ...
CVE-2025-29209CRITICAL9.8TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub...
CVE-2025-28232CRITICAL9.1Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad...
CVE-2025-28230CRITICAL9.1Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent...
CVE-2025-28229CRITICAL9.8Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic...
CVE-2025-2492CRITICAL9.2An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req...
CVE-2025-3783CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff...
CVE-2025-1863CRITICAL9.8Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se...
CVE-2025-39471CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S...
CVE-2025-42599CRITICAL9.8Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp...
CVE-2025-3762CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-28009CRITICAL9.8A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2...
CVE-2025-2947CRITICAL9.8IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now