2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-8179CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affec...
CVE-2025-6895CRITICAL9.8The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi...
CVE-2025-54416CRITICAL9.1tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with supp...
CVE-2025-54415CRITICAL9.1dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0...
CVE-2025-54385CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions bet...
CVE-2025-8173CRITICAL9.8A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected b...
CVE-2025-8169CRITICAL9.8A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPca...
CVE-2025-8168CRITICAL9.8A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function ...
CVE-2025-30135CRITICAL9.4An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur....
CVE-2025-8166CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a...
CVE-2025-46199CRITICAL9.8Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafte...
CVE-2025-29631CRITICAL9.8Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1...
CVE-2025-29629CRITICAL9.1Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1...
CVE-2025-29628CRITICAL9.4A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware befo...
CVE-2025-8159CRITICAL9.8A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLang...
CVE-2025-45777CRITICAL9.8An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass au...
CVE-2025-8125CRITICAL9.8A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some...
CVE-2025-54379CRITICAL9.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2025-54369CRITICAL9.3Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo...
CVE-2025-32429CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4...
CVE-2025-7404CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,...
CVE-2025-6260CRITICAL9.8The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta...
CVE-2025-48732CRITICAL9.8An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c...
CVE-2025-41420CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4...
CVE-2025-36548CRITICAL9.6A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of W...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now