2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-6327CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al...
CVE-2025-6325CRITICAL9.8Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es...
CVE-2025-62065CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue aff...
CVE-2025-62064CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows...
CVE-2025-62047CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects ...
CVE-2025-62016CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from...
CVE-2025-60245CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injecti...
CVE-2025-60243CRITICAL9.8Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-c...
CVE-2025-60235CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium)...
CVE-2025-60207CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce ...
CVE-2025-60195CRITICAL9.8Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalatio...
CVE-2025-58998CRITICAL9.8Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue...
CVE-2025-58996CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows...
CVE-2025-58636CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows O...
CVE-2025-58627CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore all...
CVE-2025-53283CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploa...
CVE-2025-53242CRITICAL9.8Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Sei...
CVE-2025-52773CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Paym...
CVE-2025-49393CRITICAL9.8Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.T...
CVE-2025-49372CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticke...
CVE-2025-48089CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Edu...
CVE-2025-47588CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules f...
CVE-2025-32222CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic all...
CVE-2025-64164CRITICAL9.8Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi...
CVE-2025-64163CRITICAL9.8DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now