2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10870CRITICAL9.3SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab...
CVE-2025-64338CRITICAL9ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use...
CVE-2025-12352CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-64180CRITICAL10Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul...
CVE-2025-11546CRITICAL9.3CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C...
CVE-2025-62630CRITICAL9.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories...
CVE-2025-59171CRITICAL9.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories...
CVE-2025-12488CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-12487CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-27918CRITICAL9.8An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7....
CVE-2025-6327CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al...
CVE-2025-6325CRITICAL9.8Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es...
CVE-2025-62065CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue aff...
CVE-2025-62064CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows...
CVE-2025-62047CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects ...
CVE-2025-62016CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from...
CVE-2025-60245CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injecti...
CVE-2025-60243CRITICAL9.8Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-c...
CVE-2025-60235CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium)...
CVE-2025-60207CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce ...
CVE-2025-60195CRITICAL9.8Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalatio...
CVE-2025-58998CRITICAL9.8Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue...
CVE-2025-58996CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows...
CVE-2025-58636CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows O...
CVE-2025-58627CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now