2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-59944CRITICAL9.8Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the wa...
CVE-2025-59943CRITICAL9.8phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e...
CVE-2025-49844CRITICAL9.9Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ...
CVE-2025-10729CRITICAL9.4The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creatio...
CVE-2025-10728CRITICAL9.4When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading t...
CVE-2025-9286CRITICAL9.8The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza...
CVE-2025-9209CRITICAL9.8The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3....
CVE-2025-7721CRITICAL9.8The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Incl...
CVE-2025-40636CRITICAL9.3SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri...
CVE-2025-10726CRITICAL9.1The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a...
CVE-2025-10547CRITICAL9.8An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all...
CVE-2025-6388CRITICAL9.8The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-61605CRITICAL9.8WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In...
CVE-2025-61603CRITICAL9.8WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi...
CVE-2025-59407CRITICAL9.8The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco...
CVE-2025-59403CRITICAL9.8The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat...
CVE-2025-59743CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59742CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59741CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59740CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59739CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59738CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59737CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59736CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59735CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now