2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1550CRITICAL9.8The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually const...
CVE-2025-1661CRITICAL9.8The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2025-27925CRITICAL9.8Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
CVE-2025-25306CRITICAL9.3Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate t...
CVE-2025-24813CRITICAL9.8Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malic...
CVE-2025-25977CRITICAL9.8An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
CVE-2025-25940CRITICAL9.8VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.
CVE-2025-26936CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework all...
CVE-2025-26916CRITICAL9Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-2152CRITICAL9.8A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ...
CVE-2025-1497CRITICAL9.8A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-g...
CVE-2025-1945CRITICAL9.8picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag...
CVE-2025-2115CRITICAL9.8A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affec...
CVE-2025-2113CRITICAL9.8A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this is...
CVE-2025-2112CRITICAL9.8A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declar...
CVE-2025-1323CRITICAL9.8The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'data...
CVE-2025-0177CRITICAL9.8The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080...
CVE-2025-2097CRITICAL9.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue...
CVE-2025-2096CRITICAL9.8A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects ...
CVE-2025-2095CRITICAL9.8A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the funct...
CVE-2025-2094CRITICAL9.8A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this is...
CVE-2025-27603CRITICAL9.1XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't ...
CVE-2025-27519CRITICAL9.3Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for productio...
CVE-2025-2088CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affec...
CVE-2025-1315CRITICAL9.8The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now