2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-47569CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer...
CVE-2025-32486CRITICAL9.8Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T...
CVE-2025-10183CRITICAL9.1A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthent...
CVE-2025-9994CRITICAL9.8The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing ...
CVE-2025-54236CRITICAL9.1Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-40804CRITICAL9.3A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica...
CVE-2025-40795CRITICAL9.8A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2025-40594CRITICAL9.8A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ...
CVE-2025-10134CRITICAL9.1The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi...
CVE-2025-10123CRITICAL9.8A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502...
CVE-2025-42958CRITICAL9.1Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high priv...
CVE-2025-42944CRITICAL10Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through th...
CVE-2025-42922CRITICAL9.9SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available servic...
CVE-2025-10118CRITICAL9.8A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The...
CVE-2025-10114CRITICAL9.8A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file ...
CVE-2025-10113CRITICAL9.8A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un...
CVE-2025-10112CRITICAL9.8A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk...
CVE-2025-58746CRITICAL9The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashbo...
CVE-2025-10111CRITICAL9.8A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a...
CVE-2025-10109CRITICAL9.8A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin...
CVE-2025-58450CRITICAL9.3pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible...
CVE-2025-10108CRITICAL9.8A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the...
CVE-2025-54994CRITICAL9.3@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13...
CVE-2025-10104CRITICAL9.8A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func...
CVE-2025-9114CRITICAL9.8The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now