2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32569CRITICAL9.8Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.Thi...
CVE-2025-32568CRITICAL9.8Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object ...
CVE-2025-32565CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Produc...
CVE-2025-32519CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32491CRITICAL9.8Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analy...
CVE-2025-31599CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Produ...
CVE-2025-31565CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez ...
CVE-2025-32743CRITICAL9In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca...
CVE-2025-32755CRITICAL9.1In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De...
CVE-2025-32754CRITICAL9.1In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on...
CVE-2025-22375CRITICAL9.3An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an...
CVE-2025-32206CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows U...
CVE-2025-32202CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articul...
CVE-2025-32140CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnai...
CVE-2025-27690CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent...
CVE-2025-3115CRITICAL9.8Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing th...
CVE-2025-3114CRITICAL9.4Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute wit...
CVE-2025-32695CRITICAL9.8Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege E...
CVE-2025-32642CRITICAL10Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issu...
CVE-2025-32641CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor all...
CVE-2025-32576CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web She...
CVE-2025-32496CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web...
CVE-2025-31033CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site ...
CVE-2025-31002CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Maliciou...
CVE-2025-32375CRITICAL9.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now