2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-55299CRITICAL9.4VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through ...
CVE-2025-55293CRITICAL9.8Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi...
CVE-2025-55205CRITICAL9Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu...
CVE-2025-27909CRITICAL9.8IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr...
CVE-2025-31715CRITICAL9.8In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2025-9090CRITICAL9.8A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/te...
CVE-2025-9089CRITICAL9.8A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform...
CVE-2025-9088CRITICAL9.8A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the...
CVE-2025-9087CRITICAL9.8A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/...
CVE-2025-8898CRITICAL9.8The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account ...
CVE-2025-7441CRITICAL9.8The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42...
CVE-2025-52618CRITICAL9.8HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential...
CVE-2025-9060CRITICAL9.1A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server...
CVE-2025-8995CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati...
CVE-2025-54466CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum ...
CVE-2025-9053CRITICAL9.8A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of...
CVE-2025-9052CRITICAL9.8A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /...
CVE-2025-9051CRITICAL9.8A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown fun...
CVE-2025-9050CRITICAL9.8A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown fu...
CVE-2025-54473CRITICAL9.2An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. T...
CVE-2025-9047CRITICAL9.8A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-9028CRITICAL9.8A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /a...
CVE-2025-9027CRITICAL9.8A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of th...
CVE-2025-9026CRITICAL9.8A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cg...
CVE-2025-9024CRITICAL9.8A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now