2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-9599CRITICAL9.8A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unk...
CVE-2025-9598CRITICAL9.8A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of ...
CVE-2025-9597CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the ...
CVE-2025-9596CRITICAL9.8A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the fil...
CVE-2025-9594CRITICAL9.8A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown funct...
CVE-2025-9593CRITICAL9.8A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /repo...
CVE-2025-9592CRITICAL9.8A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing...
CVE-2025-9582CRITICAL9.8A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Execut...
CVE-2025-9581CRITICAL9.8A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt....
CVE-2025-58059CRITICAL9.1Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be...
CVE-2025-58048CRITICAL9.9Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments funct...
CVE-2025-57819CRITICAL9.8FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins...
CVE-2025-55583CRITICAL9.8D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in...
CVE-2025-54738CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth...
CVE-2025-54725CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th...
CVE-2025-54720CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest A...
CVE-2025-52761CRITICAL9.8Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection...
CVE-2025-49388CRITICAL9.8Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Esca...
CVE-2025-49387CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor For...
CVE-2025-48100CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu...
CVE-2025-39496CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ...
CVE-2025-54762CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-53970CRITICAL9.8SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb...
CVE-2025-7955CRITICAL9.8The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi...
CVE-2025-34523CRITICAL9.8A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now