2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-0890CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B...
CVE-2025-22204CRITICAL9.8Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote ...
CVE-2025-24957CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24906CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24905CRITICAL9.8WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio...
CVE-2025-24370CRITICAL9.3Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are...
CVE-2025-22978CRITICAL9.8eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
CVE-2025-20634CRITICAL9.8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio...
CVE-2025-0950CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects...
CVE-2025-0946CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne...
CVE-2025-0945CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an un...
CVE-2025-0944CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue aff...
CVE-2025-0943CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulner...
CVE-2025-24891CRITICAL9.6Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver...
CVE-2025-22957CRITICAL9.8A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without an...
CVE-2025-23215CRITICAL9.3PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing key...
CVE-2025-0929CRITICAL9.8SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete a...
CVE-2025-0493CRITICAL9.8The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limit...
CVE-2025-0881CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unkn...
CVE-2025-0880CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unkn...
CVE-2025-0147CRITICAL9.8Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation o...
CVE-2025-24503CRITICAL9.3A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM...
CVE-2025-0680CRITICAL9.8Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attac...
CVE-2025-0874CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management ...
CVE-2025-0498CRITICAL9.8A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now