2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12674CRITICAL9.8The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-11749CRITICAL9.8The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-12735CRITICAL9.8The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio...
CVE-2025-52910CRITICAL9.8An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 148...
CVE-2025-47776CRITICAL9.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===...
CVE-2025-12108CRITICAL9.3The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration...
CVE-2025-61956CRITICAL9.8Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access an...
CVE-2025-61945CRITICAL9.8Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without auth...
CVE-2025-54863CRITICAL9.8Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration f...
CVE-2025-12682CRITICAL9.8The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis...
CVE-2025-12493CRITICAL9.8The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2025-12158CRITICAL9.8The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec...
CVE-2025-11008CRITICAL9.8The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-11007CRITICAL9.8The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che...
CVE-2025-12642CRITICAL9.1lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited...
CVE-2025-12531CRITICAL9.1IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) atta...
CVE-2025-12463CRITICAL9.8An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` paramet...
CVE-2025-11953CRITICAL9.8The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default...
CVE-2025-63453CRITICAL9.8Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.
CVE-2025-63452CRITICAL9.4Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
CVE-2025-63451CRITICAL9.8Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
CVE-2025-8900CRITICAL9.8The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi...
CVE-2025-0987CRITICAL9.9Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection....
CVE-2025-12622CRITICAL9.8A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd o...
CVE-2025-12619CRITICAL9.8A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now