2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32660CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shel...
CVE-2025-32658CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects He...
CVE-2025-32652CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicio...
CVE-2025-32648CRITICAL9.8Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.Thi...
CVE-2025-32636CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local...
CVE-2025-32626CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Man...
CVE-2025-32583CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code...
CVE-2025-32572CRITICAL9.8Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue ...
CVE-2025-31380CRITICAL9.8Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-li...
CVE-2025-29043CRITICAL9.8An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
CVE-2025-29042CRITICAL9.8An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the fu...
CVE-2025-27302CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Mar...
CVE-2025-27287CRITICAL9.8Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz ssquiz allows Object Injection.This issue affects SS ...
CVE-2025-27286CRITICAL9.8Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injecti...
CVE-2025-27282CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator ...
CVE-2025-24577CRITICAL9.8Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con...
CVE-2025-22655CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD –...
CVE-2025-3651CRITICAL9.3Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allo...
CVE-2025-29047CRITICAL9.8Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra...
CVE-2025-29046CRITICAL9.8Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra...
CVE-2025-29045CRITICAL9.8Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_te...
CVE-2025-29044CRITICAL9.8Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via th...
CVE-2025-29041CRITICAL9.8An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t...
CVE-2025-29040CRITICAL9.8An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t...
CVE-2025-2188CRITICAL9.1There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now