2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-50518CRITICAL9.8A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library. This...
CVE-2025-7972CRITICAL9.1A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘developme...
CVE-2025-43983CRITICAL9.1KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/...
CVE-2025-27845CRITICAL9.8In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in e...
CVE-2025-7353CRITICAL9.3A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Module...
CVE-2025-43984CRITICAL9.8An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_...
CVE-2025-8963CRITICAL9.8A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality...
CVE-2025-8960CRITICAL9.8A vulnerability has been found in Campcodes Online Flight Booking Management System 1.0. Affected by this issue is some ...
CVE-2025-8957CRITICAL9.8A vulnerability was determined in Campcodes Online Flight Booking Management System 1.0. Affected is an unknown function...
CVE-2025-54707CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp...
CVE-2025-54701CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54700CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54693CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell...
CVE-2025-54686CRITICAL9.8Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affe...
CVE-2025-54678CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas...
CVE-2025-54669CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG m...
CVE-2025-52720CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2025-49887CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCom...
CVE-2025-49059CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve...
CVE-2025-48293CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-28979CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-25174CRITICAL10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-24775CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Sh...
CVE-2025-8955CRITICAL9.8A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of ...
CVE-2025-8943CRITICAL9.8The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Se...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now