2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-3085CRITICAL9.8A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails t...
CVE-2025-2237CRITICAL9.8The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u...
CVE-2025-30065CRITICAL9.8Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar...
CVE-2025-31095CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard ...
CVE-2025-31087CRITICAL9.8Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerc...
CVE-2025-31084CRITICAL9.8Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Obje...
CVE-2025-30971CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Rand...
CVE-2025-30911CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allo...
CVE-2025-30886CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help De...
CVE-2025-30878CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-...
CVE-2025-30876CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads...
CVE-2025-30870CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30849CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30774CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker...
CVE-2025-30622CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash...
CVE-2025-3045CRITICAL9.8A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management Sy...
CVE-2025-3042CRITICAL9.8A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability a...
CVE-2025-3041CRITICAL9.8A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an...
CVE-2025-3040CRITICAL9.8A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by ...
CVE-2025-31194CRITICAL9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S...
CVE-2025-31183CRITICAL9.8The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 1...
CVE-2025-31182CRITICAL9.8This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequ...
CVE-2025-30465CRITICAL9.8A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, ma...
CVE-2025-30462CRITICAL9.8A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS S...
CVE-2025-30461CRITICAL9.8An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in mac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now