2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-53283CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploa...
CVE-2025-53242CRITICAL9.8Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Sei...
CVE-2025-52773CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Paym...
CVE-2025-49393CRITICAL9.8Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.T...
CVE-2025-49372CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticke...
CVE-2025-48089CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Edu...
CVE-2025-47588CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules f...
CVE-2025-32222CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic all...
CVE-2025-64164CRITICAL9.8Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi...
CVE-2025-64163CRITICAL9.8DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist...
CVE-2025-62596CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie...
CVE-2025-62161CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul...
CVE-2025-63334CRITICAL9.8PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm...
CVE-2025-63416CRITICAL9.1** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self...
CVE-2025-55343CRITICAL9.9Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d...
CVE-2025-56231CRITICAL9.1Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta...
CVE-2025-10713CRITICAL9.1An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par...
CVE-2025-45378CRITICAL9.1Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass...
CVE-2025-20358CRITICAL9.8A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat...
CVE-2025-20354CRITICAL9.8A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ...
CVE-2025-63601CRITICAL9.9Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up...
CVE-2025-61304CRITICAL9.8OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
CVE-2025-64459CRITICAL9.1An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ...
CVE-2025-47151CRITICAL9.8A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ...
CVE-2025-55108CRITICAL10The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now