2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-22371CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (S...
CVE-2025-3559CRITICAL9.8A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the...
CVE-2025-3558CRITICAL9.8A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown par...
CVE-2025-3553CRITICAL9.8A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_de...
CVE-2025-0129CRITICAL9.3An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma A...
CVE-2025-3439CRITICAL9.8The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ...
CVE-2025-23391CRITICAL9.1A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password ...
CVE-2025-32607CRITICAL9.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Inje...
CVE-2025-32603CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users...
CVE-2025-32579CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload ...
CVE-2025-32577CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32569CRITICAL9.8Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.Thi...
CVE-2025-32568CRITICAL9.8Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object ...
CVE-2025-32565CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Produc...
CVE-2025-32519CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32491CRITICAL9.8Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analy...
CVE-2025-31599CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Produ...
CVE-2025-31565CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez ...
CVE-2025-32743CRITICAL9In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca...
CVE-2025-32755CRITICAL9.1In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De...
CVE-2025-32754CRITICAL9.1In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on...
CVE-2025-22375CRITICAL9.3An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an...
CVE-2025-32206CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows U...
CVE-2025-32202CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articul...
CVE-2025-32140CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now