2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-36904CRITICAL9.8WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.
CVE-2025-36897CRITICAL9.8In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2025-36896CRITICAL9.8WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.
CVE-2025-36890CRITICAL9.8Elevation of Privilege
CVE-2025-9928CRITICAL9.8A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown fu...
CVE-2025-9927CRITICAL9.8A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown functio...
CVE-2025-55747CRITICAL9.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6....
CVE-2025-9926CRITICAL9.8A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the fil...
CVE-2025-9925CRITICAL9.8A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of t...
CVE-2025-53690CRITICAL9Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a...
CVE-2025-9924CRITICAL9.8A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of...
CVE-2025-56752CRITICAL9.4A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth...
CVE-2025-9919CRITICAL9.8A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of...
CVE-2025-57148CRITICAL9.1phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la...
CVE-2025-57052CRITICAL9.8cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c...
CVE-2025-53693CRITICAL9.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex...
CVE-2025-1740CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas...
CVE-2025-58210CRITICAL9.8Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access C...
CVE-2025-9847CRITICAL9.8A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of t...
CVE-2025-9840CRITICAL9.8A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function...
CVE-2025-9839CRITICAL9.8A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a...
CVE-2025-9838CRITICAL9.8A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown functio...
CVE-2025-26416CRITICAL9.8In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. ...
CVE-2025-22435CRITICAL9.8In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired d...
CVE-2025-22429CRITICAL9.8In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could le...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now