2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27690CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent...
CVE-2025-3115CRITICAL9.8Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing th...
CVE-2025-3114CRITICAL9.4Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute wit...
CVE-2025-32695CRITICAL9.8Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege E...
CVE-2025-32642CRITICAL10Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issu...
CVE-2025-32641CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor all...
CVE-2025-32576CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web She...
CVE-2025-32496CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web...
CVE-2025-31033CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site ...
CVE-2025-31002CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Maliciou...
CVE-2025-32375CRITICAL9.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2025-27797CRITICAL9.8OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a...
CVE-2025-32461CRITICAL9.9wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The...
CVE-2025-32460CRITICAL9.1GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportVie...
CVE-2025-30282CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that c...
CVE-2025-30281CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-24447CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2025-24446CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-22871CRITICAL9.1The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit...
CVE-2025-25226CRITICAL9.8Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database packag...
CVE-2025-32028CRITICAL9.9HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX...
CVE-2025-32020CRITICAL9.3The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper...
CVE-2025-22466CRITICAL9.6Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica...
CVE-2025-31330CRITICAL9.9SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo...
CVE-2025-30016CRITICAL9.8SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now