2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1066CRITICAL9.8OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campai...
CVE-2025-23114CRITICAL9A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected ...
CVE-2025-0960CRITICAL9.8AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an att...
CVE-2025-24971CRITICAL9.5DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Co...
CVE-2025-0364CRITICAL9.8BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via...
CVE-2025-24677CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import...
CVE-2025-22699CRITICAL9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele...
CVE-2025-1020CRITICAL9.8Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption a...
CVE-2025-1017CRITICAL9.8Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs...
CVE-2025-1016CRITICAL9.8Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, a...
CVE-2025-1009CRITICAL9.8An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This v...
CVE-2025-0890CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B...
CVE-2025-22204CRITICAL9.8Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote ...
CVE-2025-24957CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24906CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24905CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24370CRITICAL9.3Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are...
CVE-2025-22978CRITICAL9.8eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
CVE-2025-20634CRITICAL9.8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio...
CVE-2025-0950CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects...
CVE-2025-0946CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne...
CVE-2025-0945CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an un...
CVE-2025-0944CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue aff...
CVE-2025-0943CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulner...
CVE-2025-24891CRITICAL9.6Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now