2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10437CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni...
CVE-2025-12057CRITICAL9.8The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ...
CVE-2025-13051CRITICAL9.3When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac...
CVE-2025-64325CRITICAL9Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use...
CVE-2025-63217CRITICAL9.8The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev...
CVE-2025-63216CRITICAL10The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across...
CVE-2025-63228CRITICAL9.8The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu...
CVE-2025-63225CRITICAL9.8The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au...
CVE-2025-54321CRITICAL9.8In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an ema...
CVE-2025-63695CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
CVE-2025-63694CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
CVE-2025-56643CRITICAL9.1Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre...
CVE-2025-9312CRITICAL9.8A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP...
CVE-2025-41348CRITICAL9.8SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,...
CVE-2025-13344CRITICAL9.8A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a...
CVE-2025-41734CRITICAL9.8An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.
CVE-2025-41733CRITICAL9.8The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthentica...
CVE-2025-41347CRITICAL9.8Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerabili...
CVE-2025-41346CRITICAL9.8Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers...
CVE-2025-40549CRITICAL9.1A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to a...
CVE-2025-40548CRITICAL9.1A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges ...
CVE-2025-40547CRITICAL9.1A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privile...
CVE-2025-13323CRITICAL9.8A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function o...
CVE-2025-13305CRITICAL9.8A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects...
CVE-2025-13303CRITICAL9.8A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown fu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now