2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65008 | CRITICAL | 9.4 | 2.7% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ... |
| CVE-2025-14860 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. |
| CVE-2025-10910 | CRITICAL | 9.3 | 0.4% | Dec 18, 2025 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online... |
| CVE-2025-66078 | CRITICAL | 9.1 | 0.3% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hote... |
| CVE-2025-66074 | CRITICAL | 9 | 0.2% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversa... |
| CVE-2025-64374 | CRITICAL | 9.9 | 0.3% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Fil... |
| CVE-2025-64233 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects C... |
| CVE-2025-64231 | CRITICAL | 9.9 | 0.3% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google S... |
| CVE-2025-64227 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows O... |
| CVE-2025-64206 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jann... |
| CVE-2025-64188 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affec... |
| CVE-2025-60180 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows O... |
| CVE-2025-60178 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection... |
| CVE-2025-60174 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contac... |
| CVE-2025-60091 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object I... |
| CVE-2025-60090 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injec... |
| CVE-2025-60089 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Objec... |
| CVE-2025-60062 | CRITICAL | 9.3 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer t... |
| CVE-2025-58951 | CRITICAL | 9.3 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance S... |
| CVE-2025-58935 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54723 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue aff... |
| CVE-2025-53433 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68435 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne... |
| CVE-2025-68145 | CRITICAL | 9.1 | 6.2% | Dec 17, 2025 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat... |
| CVE-2025-14833 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now