2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-0180CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. ...
CVE-2025-1177CRITICAL9.8A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import...
CVE-2025-1144CRITICAL9.8School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view ...
CVE-2025-1168CRITICAL9.8A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. Th...
CVE-2025-1167CRITICAL9.8A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected...
CVE-2025-1160CRITICAL9.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2025-24016CRITICAL9.9Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2025-24032CRITICAL9.2PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if ce...
CVE-2025-0316CRITICAL9.8The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including...
CVE-2025-24028CRITICAL9.6Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into...
CVE-2025-1113CRITICAL9.8A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the functi...
CVE-2025-1104CRITICAL9.8A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown ...
CVE-2025-1107CRITICAL9.9Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker t...
CVE-2025-25167CRITICAL9.8Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorre...
CVE-2025-25163CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Im...
CVE-2025-25107CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forger...
CVE-2025-25106CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross S...
CVE-2025-25101CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery....
CVE-2025-1077CRITICAL9.5A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS,...
CVE-2025-1061CRITICAL9.8The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin...
CVE-2025-0674CRITICAL9.8Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the ...
CVE-2025-24786CRITICAL9.1WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d...
CVE-2025-22992CRITICAL9.8A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili...
CVE-2025-24981CRITICAL9.3MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions...
CVE-2025-0982CRITICAL10Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now