2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-28955HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Play...
CVE-2025-24779HIGH8.8Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: f...
CVE-2025-24777HIGH8.8Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter...
CVE-2025-54043HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP f...
CVE-2025-54026HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBa...
CVE-2025-53990HIGH7.2Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.Thi...
CVE-2025-48301HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP f...
CVE-2025-48299HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExt...
CVE-2025-48161HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT...
CVE-2025-48153HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows St...
CVE-2025-7699HIGH7.1An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to c...
CVE-2025-6993HIGH8.8The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the...
CVE-2025-40985HIGH8.3SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an atta...
CVE-2025-7359HIGH8.2The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici...
CVE-2025-6043HIGH8.1The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F...
CVE-2025-52690HIGH8.1Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially ...
CVE-2025-53028HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-53027HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-53024HIGH8.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-50106HIGH8.1Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2025-50105HIGH8.1Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administra...
CVE-2025-50069HIGH7.7Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 a...
CVE-2025-50063HIGH7.3Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451....
CVE-2025-50062HIGH8.1Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro...
CVE-2025-50060HIGH8.1Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now