2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1104CRITICAL9.8A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown ...
CVE-2025-1107CRITICAL9.9Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker t...
CVE-2025-25167CRITICAL9.8Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorre...
CVE-2025-25163CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Im...
CVE-2025-25107CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forger...
CVE-2025-25106CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross S...
CVE-2025-25101CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery....
CVE-2025-1077CRITICAL9.5A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS,...
CVE-2025-1061CRITICAL9.8The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin...
CVE-2025-0674CRITICAL9.8Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the ...
CVE-2025-24786CRITICAL9.1WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d...
CVE-2025-22992CRITICAL9.8A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili...
CVE-2025-24981CRITICAL9.3MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions...
CVE-2025-0982CRITICAL10Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra...
CVE-2025-1066CRITICAL9.8OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campai...
CVE-2025-23114CRITICAL9A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected ...
CVE-2025-0960CRITICAL9.8AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an att...
CVE-2025-24971CRITICAL9.5DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Co...
CVE-2025-0364CRITICAL9.8BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via...
CVE-2025-24677CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import...
CVE-2025-22699CRITICAL9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-1020CRITICAL9.8Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption a...
CVE-2025-1017CRITICAL9.8Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs...
CVE-2025-1016CRITICAL9.8Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, a...
CVE-2025-1009CRITICAL9.8An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now