2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22609 | CRITICAL | 10 | 0.7% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-0637 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the ap... |
| CVE-2025-23006 | CRITICAL | 9.8 | 23.4% | Jan 23, 2025 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Manageme... |
| CVE-2025-20156 | CRITICAL | 9.9 | 1.2% | Jan 22, 2025 | A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privil... |
| CVE-2025-23914 | CRITICAL | 9.8 | 0.5% | Jan 22, 2025 | Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard ... |
| CVE-2025-23953 | CRITICAL | 10 | 0.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web S... |
| CVE-2025-23942 | CRITICAL | 9.1 | 2.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Uplo... |
| CVE-2025-23932 | CRITICAL | 9.8 | 0.7% | Jan 22, 2025 | Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue af... |
| CVE-2025-23931 | CRITICAL | 9.3 | 0.5% | Jan 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliver Fuhrmann Wo... |
| CVE-2025-23921 | CRITICAL | 9 | 0.5% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-upload... |
| CVE-2025-23918 | CRITICAL | 9.9 | 0.6% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-br... |
| CVE-2025-21556 | CRITICAL | 9.9 | 0.6% | Jan 21, 2025 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). ... |
| CVE-2025-21547 | CRITICAL | 9.1 | 0.6% | Jan 21, 2025 | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ... |
| CVE-2025-21535 | CRITICAL | 9.8 | 0.8% | Jan 21, 2025 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2025-21524 | CRITICAL | 9.8 | 0.7% | Jan 21, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics ... |
| CVE-2025-24024 | CRITICAL | 9.1 | 0.6% | Jan 21, 2025 | Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member ... |
| CVE-2025-0377 | CRITICAL | 9.1 | 0.7% | Jan 21, 2025 | HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted... |
| CVE-2025-22723 | CRITICAL | 9.1 | 0.5% | Jan 21, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with ... |
| CVE-2025-22553 | CRITICAL | 9.3 | 0.3% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in dhananjaysingh Mul... |
| CVE-2025-23220 | CRITICAL | 9.8 | 0.6% | Jan 20, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-23219 | CRITICAL | 9.8 | 0.6% | Jan 20, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-23218 | CRITICAL | 9.8 | 0.6% | Jan 20, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-0585 | CRITICAL | 9.8 | 0.7% | Jan 20, 2025 | The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject... |
| CVE-2025-0565 | CRITICAL | 9.8 | 1.4% | Jan 19, 2025 | A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona... |
| CVE-2025-0564 | CRITICAL | 9.8 | 0.7% | Jan 19, 2025 | A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now