2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40636 | CRITICAL | 9.3 | 0.3% | Oct 3, 2025 | SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri... |
| CVE-2025-10726 | CRITICAL | 9.1 | 0.4% | Oct 3, 2025 | The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a... |
| CVE-2025-10547 | CRITICAL | 9.8 | 0.6% | Oct 3, 2025 | An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all... |
| CVE-2025-6388 | CRITICAL | 9.8 | 0.5% | Oct 3, 2025 | The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-61605 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In... |
| CVE-2025-61603 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi... |
| CVE-2025-59407 | CRITICAL | 9.8 | 0.5% | Oct 2, 2025 | The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco... |
| CVE-2025-59403 | CRITICAL | 9.8 | 1.0% | Oct 2, 2025 | The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat... |
| CVE-2025-59743 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59742 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59741 | CRITICAL | 9.8 | 1.3% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59740 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59739 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59738 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59737 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59736 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59735 | CRITICAL | 9.8 | 1.5% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-41064 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as... |
| CVE-2025-9697 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2025-11221 | CRITICAL | 9.4 | 0.3% | Oct 2, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero... |
| CVE-2025-61588 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture.... |
| CVE-2025-59951 | CRITICAL | 9.1 | 4.7% | Oct 1, 2025 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici... |
| CVE-2025-59681 | CRITICAL | 9.8 | 0.6% | Oct 1, 2025 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query... |
| CVE-2025-8679 | CRITICAL | 9.8 | 0.3% | Oct 1, 2025 | In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure... |
| CVE-2025-61045 | CRITICAL | 9.8 | 1.5% | Oct 1, 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now