2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-67928CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot...
CVE-2025-67924CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to...
CVE-2025-67911CRITICAL9.8Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti...
CVE-2025-67910CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload...
CVE-2025-23993CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr...
CVE-2025-23504CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo...
CVE-2025-15346CRITICAL9.3A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ...
CVE-2025-69264CRITICAL9.8pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ...
CVE-2025-68705CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai...
CVE-2025-61492CRITICAL10A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e...
CVE-2025-12543CRITICAL9.6A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The...
CVE-2025-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...
CVE-2025-32303CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ...
CVE-2025-68637CRITICAL9.1The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This...
CVE-2025-15018CRITICAL9.8The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to...
CVE-2025-15471CRITICAL9.8A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform...
CVE-2025-30996CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi...
CVE-2025-14942CRITICAL9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to ...
CVE-2025-60534CRITICAL9.8Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv...
CVE-2025-39477CRITICAL9.8Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-65212CRITICAL9.8An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev...
CVE-2025-60262CRITICAL9.8An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi...
CVE-2025-15001CRITICAL9.8The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2025-14996CRITICAL9.8The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun...
CVE-2025-15385CRITICAL9.8Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now