2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25570CRITICAL9.8Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
CVE-2025-22952CRITICAL9.8elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie...
CVE-2025-0767CRITICAL9.8WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in ...
CVE-2025-27154CRITICAL9.8Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store ...
CVE-2025-1751CRITICAL9.8A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker t...
CVE-2025-21796CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing ...
CVE-2025-25790CRITICAL9.8An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers ...
CVE-2025-25789CRITICAL9.8FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controlle...
CVE-2025-25785CRITICAL9.1JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.ph...
CVE-2025-25784CRITICAL9.8An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to...
CVE-2025-25783CRITICAL9.8An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute...
CVE-2025-1716CRITICAL9.8picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses P...
CVE-2025-25521CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2025-25520CRITICAL9.8Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25519CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25517CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
CVE-2025-25516CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-27135CRITICAL9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL i...
CVE-2025-26974CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Mu...
CVE-2025-26971CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker...
CVE-2025-26966CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.Thi...
CVE-2025-26943CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy...
CVE-2025-26900CRITICAL9.8Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue a...
CVE-2025-1676CRITICAL9.8A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulne...
CVE-2025-1675CRITICAL9.1The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not chec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now