2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24102 | CRITICAL | 9.8 | 0.9% | Jan 27, 2025 | The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.... |
| CVE-2025-24093 | CRITICAL | 9.8 | 0.8% | Jan 27, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma ... |
| CVE-2025-24085 | CRITICAL | 10 | 18.7% | Jan 27, 2025 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i... |
| CVE-2025-24671 | CRITICAL | 9.8 | 0.5% | Jan 27, 2025 | Deserialization of Untrusted Data vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Object I... |
| CVE-2025-24667 | CRITICAL | 9.3 | 0.4% | Jan 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2025-24665 | CRITICAL | 9.3 | 0.4% | Jan 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2025-24664 | CRITICAL | 9.3 | 0.4% | Jan 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2025-24612 | CRITICAL | 9.3 | 0.4% | Jan 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping ... |
| CVE-2025-24601 | CRITICAL | 9.8 | 0.5% | Jan 27, 2025 | Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affe... |
| CVE-2025-0357 | CRITICAL | 9.8 | 1.1% | Jan 25, 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in th... |
| CVE-2025-24650 | CRITICAL | 9.1 | 0.6% | Jan 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a... |
| CVE-2025-24596 | CRITICAL | 9.8 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Expl... |
| CVE-2025-22612 | CRITICAL | 10 | 0.6% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-22611 | CRITICAL | 9.9 | 0.5% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-22609 | CRITICAL | 10 | 0.7% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-0637 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the ap... |
| CVE-2025-23006 | CRITICAL | 9.8 | 23.4% | Jan 23, 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Manageme... |
| CVE-2025-20156 | CRITICAL | 9.9 | 1.2% | Jan 22, 2025 | A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privil... |
| CVE-2025-23914 | CRITICAL | 9.8 | 0.5% | Jan 22, 2025 | Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard ... |
| CVE-2025-23953 | CRITICAL | 10 | 0.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web S... |
| CVE-2025-23942 | CRITICAL | 9.1 | 2.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Uplo... |
| CVE-2025-23932 | CRITICAL | 9.8 | 0.7% | Jan 22, 2025 | Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue af... |
| CVE-2025-23931 | CRITICAL | 9.3 | 0.5% | Jan 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliver Fuhrmann Wo... |
| CVE-2025-23921 | CRITICAL | 9 | 0.5% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-upload... |
| CVE-2025-23918 | CRITICAL | 9.9 | 0.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-br... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now