2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-54145CRITICAL9.1The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev...
CVE-2025-54143CRITICAL9.8Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio...
CVE-2025-9156CRITICAL9.8A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t...
CVE-2025-9155CRITICAL9.8A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func...
CVE-2025-51543CRITICAL9.8An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini...
CVE-2025-9154CRITICAL9.8A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc...
CVE-2025-55733CRITICAL9.6DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r...
CVE-2025-55306CRITICAL9.8GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F...
CVE-2025-9149CRITICAL9.8A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg...
CVE-2025-55294CRITICAL9.8screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue....
CVE-2025-54336CRITICAL9.8In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b...
CVE-2025-50567CRITICAL10Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac...
CVE-2025-8723CRITICAL9.8The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ...
CVE-2025-6758CRITICAL9.8The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the...
CVE-2025-55591CRITICAL9.8TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac param...
CVE-2025-55213CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-7693CRITICAL9.3A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller e...
CVE-2025-55299CRITICAL9.4VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through ...
CVE-2025-55293CRITICAL9.8Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi...
CVE-2025-55205CRITICAL9Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu...
CVE-2025-27909CRITICAL9.8IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr...
CVE-2025-31715CRITICAL9.8In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2025-9090CRITICAL9.8A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/te...
CVE-2025-9089CRITICAL9.8A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform...
CVE-2025-9088CRITICAL9.8A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now