2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27268CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-26970CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Ark Theme Core ark-core allows Code...
CVE-2025-26535CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin /...
CVE-2025-25150CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ...
CVE-2025-1875CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in sear...
CVE-2025-1874CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admi...
CVE-2025-1873CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescriptio...
CVE-2025-1872CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in a...
CVE-2025-1871CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" pa...
CVE-2025-1870CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in ...
CVE-2025-1869CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/c...
CVE-2025-1867CRITICAL10Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows H...
CVE-2025-1866CRITICAL10Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Po...
CVE-2025-1864CRITICAL9.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overfl...
CVE-2025-1859CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some...
CVE-2025-1858CRITICAL9.8A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unk...
CVE-2025-1857CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affe...
CVE-2025-1856CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue i...
CVE-2025-1853CRITICAL9.8A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E09...
CVE-2025-1852CRITICAL9.8A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability...
CVE-2025-1850CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by...
CVE-2025-27590CRITICAL9.8In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr...
CVE-2025-20646CRITICAL9.8In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escal...
CVE-2025-1845CRITICAL9.8A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the f...
CVE-2025-1844CRITICAL9.8A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. Affected is an unkn...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now