2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1791CRITICAL9.8A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the functio...
CVE-2025-1671CRITICAL9.8The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2025-1638CRITICAL9.8The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including...
CVE-2025-1564CRITICAL9.8The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t...
CVE-2025-27554CRITICAL9.9ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to exec...
CVE-2025-23116CRITICAL9.6An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a...
CVE-2025-23115CRITICAL9A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor w...
CVE-2025-25379CRITICAL9.6Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the ...
CVE-2025-0160CRITICAL9.8IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5...
CVE-2025-0159CRITICAL9.1IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5...
CVE-2025-22273CRITICAL9.3Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the...
CVE-2025-1570CRITICAL9.8The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-1744CRITICAL9.8Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issu...
CVE-2025-26325CRITICAL9.8ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
CVE-2025-25570CRITICAL9.8Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
CVE-2025-22952CRITICAL9.8elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie...
CVE-2025-0767CRITICAL9.8WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in ...
CVE-2025-27154CRITICAL9.8Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store ...
CVE-2025-1751CRITICAL9.8A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t...
CVE-2025-21796CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing ...
CVE-2025-25790CRITICAL9.8An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers ...
CVE-2025-25789CRITICAL9.8FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controlle...
CVE-2025-25785CRITICAL9.1JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.ph...
CVE-2025-25784CRITICAL9.8An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to...
CVE-2025-25783CRITICAL9.8An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now