2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-65008CRITICAL9.4In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ...
CVE-2025-14860CRITICAL9.8Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
CVE-2025-10910CRITICAL9.3A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online...
CVE-2025-66078CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hote...
CVE-2025-66074CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversa...
CVE-2025-64374CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Fil...
CVE-2025-64233CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects C...
CVE-2025-64231CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google S...
CVE-2025-64227CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows O...
CVE-2025-64206CRITICAL9.8Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jann...
CVE-2025-64188CRITICAL9.8Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affec...
CVE-2025-60180CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows O...
CVE-2025-60178CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection...
CVE-2025-60174CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contac...
CVE-2025-60091CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object I...
CVE-2025-60090CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injec...
CVE-2025-60089CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Objec...
CVE-2025-60062CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer t...
CVE-2025-58951CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance S...
CVE-2025-58935CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54723CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue aff...
CVE-2025-53433CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68435CRITICAL9.1Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne...
CVE-2025-68145CRITICAL9.1In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat...
CVE-2025-14833CRITICAL9.8A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now