2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12493CRITICAL9.8The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2025-12158CRITICAL9.8The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec...
CVE-2025-11008CRITICAL9.8The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-11007CRITICAL9.8The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che...
CVE-2025-12642CRITICAL9.1lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited...
CVE-2025-12531CRITICAL9.1IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) atta...
CVE-2025-12463CRITICAL9.8An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` paramet...
CVE-2025-11953CRITICAL9.8The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default...
CVE-2025-63453CRITICAL9.8Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.
CVE-2025-63452CRITICAL9.4Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
CVE-2025-63451CRITICAL9.8Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
CVE-2025-8900CRITICAL9.8The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi...
CVE-2025-0987CRITICAL9.9Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection....
CVE-2025-12622CRITICAL9.8A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd o...
CVE-2025-12619CRITICAL9.8A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/o...
CVE-2025-12618CRITICAL9.8A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIn...
CVE-2025-12617CRITICAL9.8A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_...
CVE-2025-12614CRITICAL9.8A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delet...
CVE-2025-12612CRITICAL9.8A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unkn...
CVE-2025-12611CRITICAL9.8A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of t...
CVE-2025-12608CRITICAL9.8A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknow...
CVE-2025-12607CRITICAL9.8A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the...
CVE-2025-12606CRITICAL9.8A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown proces...
CVE-2025-12605CRITICAL9.8A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of ...
CVE-2025-12604CRITICAL9.8A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now