2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-24102CRITICAL9.8The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14....
CVE-2025-24093CRITICAL9.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma ...
CVE-2025-24085CRITICAL10A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i...
CVE-2025-24671CRITICAL9.8Deserialization of Untrusted Data vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Object I...
CVE-2025-24667CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-24665CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-24664CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-24612CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping ...
CVE-2025-24601CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affe...
CVE-2025-0357CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in th...
CVE-2025-24650CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a...
CVE-2025-24596CRITICAL9.8Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite wc-product-table-lite allows Expl...
CVE-2025-22612CRITICAL10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-22611CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-22609CRITICAL10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-0637CRITICAL9.8It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the ap...
CVE-2025-23006CRITICAL9.8Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Manageme...
CVE-2025-20156CRITICAL9.9A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privil...
CVE-2025-23914CRITICAL9.8Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard ...
CVE-2025-23953CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web S...
CVE-2025-23942CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Uplo...
CVE-2025-23932CRITICAL9.8Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue af...
CVE-2025-23931CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliver Fuhrmann Wo...
CVE-2025-23921CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-upload...
CVE-2025-23918CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-br...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now