2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67928 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot... |
| CVE-2025-67924 | CRITICAL | 9.9 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to... |
| CVE-2025-67911 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti... |
| CVE-2025-67910 | CRITICAL | 9.1 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload... |
| CVE-2025-23993 | CRITICAL | 9.3 | 0.4% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr... |
| CVE-2025-23504 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo... |
| CVE-2025-15346 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ... |
| CVE-2025-69264 | CRITICAL | 9.8 | 1.0% | Jan 7, 2026 | pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ... |
| CVE-2025-68705 | CRITICAL | 9.8 | 6.6% | Jan 7, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai... |
| CVE-2025-61492 | CRITICAL | 10 | 1.9% | Jan 7, 2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e... |
| CVE-2025-12543 | CRITICAL | 9.6 | 1.2% | Jan 7, 2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The... |
| CVE-2025-47552 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is... |
| CVE-2025-32303 | CRITICAL | 9.3 | 0.2% | Jan 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ... |
| CVE-2025-68637 | CRITICAL | 9.1 | 0.2% | Jan 7, 2026 | The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This... |
| CVE-2025-15018 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to... |
| CVE-2025-15471 | CRITICAL | 9.8 | 12.1% | Jan 7, 2026 | A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform... |
| CVE-2025-30996 | CRITICAL | 9.9 | 0.4% | Jan 6, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi... |
| CVE-2025-14942 | CRITICAL | 9.8 | 0.4% | Jan 6, 2026 | wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to ... |
| CVE-2025-60534 | CRITICAL | 9.8 | 0.7% | Jan 6, 2026 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv... |
| CVE-2025-39477 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-65212 | CRITICAL | 9.8 | 4.6% | Jan 6, 2026 | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev... |
| CVE-2025-60262 | CRITICAL | 9.8 | 0.5% | Jan 6, 2026 | An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi... |
| CVE-2025-15001 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2025-14996 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun... |
| CVE-2025-15385 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now