2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-40636CRITICAL9.3SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri...
CVE-2025-10726CRITICAL9.1The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a...
CVE-2025-10547CRITICAL9.8An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all...
CVE-2025-6388CRITICAL9.8The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-61605CRITICAL9.8WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In...
CVE-2025-61603CRITICAL9.8WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi...
CVE-2025-59407CRITICAL9.8The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco...
CVE-2025-59403CRITICAL9.8The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat...
CVE-2025-59743CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59742CRITICAL9.8SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u...
CVE-2025-59741CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59740CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59739CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59738CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59737CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59736CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-59735CRITICAL9.8Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe...
CVE-2025-41064CRITICAL9.3Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as...
CVE-2025-9697CRITICAL9.8The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a...
CVE-2025-11221CRITICAL9.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero...
CVE-2025-61588CRITICAL9.3RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture....
CVE-2025-59951CRITICAL9.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici...
CVE-2025-59681CRITICAL9.8An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query...
CVE-2025-8679CRITICAL9.8In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure...
CVE-2025-61045CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now