2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1861CRITICAL9.8In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsi...
CVE-2025-2266CRITICAL9.8The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that ...
CVE-2025-28091CRITICAL9.1maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
CVE-2025-28090CRITICAL9.1maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
CVE-2025-28089CRITICAL9.1maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
CVE-2025-28087CRITICAL9.8Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
CVE-2025-25579CRITICAL9.8TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
CVE-2025-2927CRITICAL9.8A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown func...
CVE-2025-28256CRITICAL9.8An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWla...
CVE-2025-22953CRITICAL9.8A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC...
CVE-2025-30372CRITICAL9.8Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vul...
CVE-2025-22526CRITICAL9.8Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performanc...
CVE-2025-22523CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule...
CVE-2025-2859CRITICAL9.8An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the activ...
CVE-2025-28219CRITICAL9.8Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to ...
CVE-2025-2294CRITICAL9.8The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin...
CVE-2025-24383CRITICAL9.1Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-22398CRITICAL9.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-26898CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-26873CRITICAL9Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a th...
CVE-2025-29306CRITICAL9.8An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm...
CVE-2025-30367CRITICAL9.8WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3....
CVE-2025-30365CRITICAL9.8WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3....
CVE-2025-30364CRITICAL9.8WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3....
CVE-2025-30361CRITICAL9.8WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now