2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-61455CRITICAL9.8SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The...
CVE-2025-41028CRITICAL9.3A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r...
CVE-2025-61932CRITICAL9.8Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of...
CVE-2025-31342CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services...
CVE-2025-11948CRITICAL9.8Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent...
CVE-2025-11943CRITICAL9.8A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ...
CVE-2025-11942CRITICAL9.8A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ...
CVE-2025-11391CRITICAL9.8The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads d...
CVE-2025-62650CRITICAL9.9The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for...
CVE-2025-62645CRITICAL9.9The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t...
CVE-2025-62515CRITICAL9.8pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class ...
CVE-2025-56316CRITICAL9.8A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo...
CVE-2025-56221CRITICAL9.8A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut...
CVE-2025-56218CRITICAL9.8An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c...
CVE-2025-34282CRITICAL9.1ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ...
CVE-2025-8414CRITICAL9.4Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ...
CVE-2025-62353CRITICAL9.8A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo...
CVE-2025-60279CRITICAL9.6A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users...
CVE-2025-57567CRITICAL9.1A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l...
CVE-2025-49655CRITICAL9.8Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc...
CVE-2025-55100CRITICAL9.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-11849CRITICAL9.3Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1....
CVE-2025-6950CRITICAL9.9An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th...
CVE-2025-6949CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-11900CRITICAL9.8The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now