2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1716CRITICAL9.8picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses P...
CVE-2025-25521CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2025-25520CRITICAL9.8Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25519CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25517CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
CVE-2025-25516CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-27135CRITICAL9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL i...
CVE-2025-26974CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Mu...
CVE-2025-26971CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker...
CVE-2025-26966CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.Thi...
CVE-2025-26943CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy...
CVE-2025-26900CRITICAL9.8Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue a...
CVE-2025-1676CRITICAL9.8A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulne...
CVE-2025-1675CRITICAL9.1The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not chec...
CVE-2025-1128CRITICAL9.8The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is...
CVE-2025-1641CRITICAL9.8A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been classified as critical. This affects an unknown ...
CVE-2025-1640CRITICAL9.8A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some un...
CVE-2025-22974CRITICAL9.8SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTra...
CVE-2025-27140CRITICAL9.8WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions pri...
CVE-2025-25513CRITICAL9.8Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
CVE-2025-26533CRITICAL9.8An SQL injection risk was identified in the module list filter within course search.
CVE-2025-27364CRITICAL10In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dy...
CVE-2025-26201CRITICAL9.1Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attacke...
CVE-2025-1616CRITICAL9.8A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by t...
CVE-2025-1610CRITICAL9.8A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the funct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now