2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14736CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i...
CVE-2025-68717CRITICAL9.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l...
CVE-2025-68715CRITICAL9.1An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor...
CVE-2025-66916CRITICAL9.4The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression...
CVE-2025-66913CRITICAL9.8JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a...
CVE-2025-67325CRITICAL9.8Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated...
CVE-2025-61548CRITICAL9.8SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo...
CVE-2025-61546CRITICAL9.1There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W...
CVE-2025-61246CRITICAL9.8indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param...
CVE-2025-59470CRITICAL9This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal...
CVE-2025-59469CRITICAL9This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468CRITICAL9.1This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ...
CVE-2025-56425CRITICAL9.1An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto...
CVE-2025-55125CRITICAL9.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio...
CVE-2025-69258CRITICAL9.8A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta...
CVE-2025-62877CRITICAL9.8Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are...
CVE-2025-67928CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot...
CVE-2025-67924CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to...
CVE-2025-67911CRITICAL9.8Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti...
CVE-2025-67910CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload...
CVE-2025-23993CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr...
CVE-2025-23504CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo...
CVE-2025-15346CRITICAL9.3A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ...
CVE-2025-69264CRITICAL9.8pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ...
CVE-2025-68705CRITICAL9.8RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now