2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-60206CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio...
CVE-2025-60039CRITICAL9.8Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa:...
CVE-2025-59557CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts A...
CVE-2025-59007CRITICAL9.8Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-gri...
CVE-2025-58963CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a W...
CVE-2025-57870CRITICAL10A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes...
CVE-2025-52758CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicio...
CVE-2025-49931CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSear...
CVE-2025-49915CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al...
CVE-2025-49901CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-l...
CVE-2025-49380CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder ...
CVE-2025-49060CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell ...
CVE-2025-48106CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious F...
CVE-2025-56447CRITICAL9.8TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
CVE-2025-41108CRITICAL9.8The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to t...
CVE-2025-41723CRITICAL9.8The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ...
CVE-2025-62481CRITICAL9.8Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support...
CVE-2025-61757CRITICAL9.8Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers...
CVE-2025-53072CRITICAL9.8Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support...
CVE-2025-53037CRITICAL9.8Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-60772CRITICAL9.8Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen...
CVE-2025-11534CRITICAL9.3The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al...
CVE-2025-11625CRITICAL9.8Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa...
CVE-2025-11624CRITICAL9.8Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger...
CVE-2025-10640CRITICAL9.8An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now