2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-56157CRITICAL9.8Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu...
CVE-2025-64236CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse....
CVE-2025-14879CRITICAL9.8A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange...
CVE-2025-63389CRITICAL9.8A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ...
CVE-2025-63388CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f...
CVE-2025-63386CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en...
CVE-2025-14878CRITICAL9.8A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele...
CVE-2025-14877CRITICAL9.8A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file...
CVE-2025-7358CRITICAL9.8Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T...
CVE-2025-65008CRITICAL9.4In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ...
CVE-2025-14860CRITICAL9.8Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
CVE-2025-10910CRITICAL9.3A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online...
CVE-2025-66078CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hote...
CVE-2025-66074CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversa...
CVE-2025-64374CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Fil...
CVE-2025-64233CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects C...
CVE-2025-64231CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google S...
CVE-2025-64227CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows O...
CVE-2025-64206CRITICAL9.8Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jann...
CVE-2025-64188CRITICAL9.8Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affec...
CVE-2025-60180CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows O...
CVE-2025-60178CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection...
CVE-2025-60174CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contac...
CVE-2025-60091CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object I...
CVE-2025-60090CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now