2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1941CRITICAL9.1Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b...
CVE-2025-1906CRITICAL9.8A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulner...
CVE-2025-1307CRITICAL9.8The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news...
CVE-2025-1903CRITICAL9.8A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects som...
CVE-2025-1902CRITICAL9.8A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability ...
CVE-2025-1901CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This af...
CVE-2025-1900CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this...
CVE-2025-0912CRITICAL9.8The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3....
CVE-2025-1894CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by ...
CVE-2025-1890CRITICAL9.8A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function han...
CVE-2025-26206CRITICAL9Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges v...
CVE-2025-1889CRITICAL9.8picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An atta...
CVE-2025-1876CRITICAL9.8A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the...
CVE-2025-27270CRITICAL9.8Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all...
CVE-2025-27268CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-26970CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Ark Theme Core ark-core allows Code...
CVE-2025-26535CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin /...
CVE-2025-25150CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ...
CVE-2025-1875CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in sear...
CVE-2025-1874CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admi...
CVE-2025-1873CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescriptio...
CVE-2025-1872CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in a...
CVE-2025-1871CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" pa...
CVE-2025-1870CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in ...
CVE-2025-1869CRITICAL9.8SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now