2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-54442CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54440CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54438CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54120CRITICAL9.3PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,...
CVE-2025-8044CRITICAL9.8Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a...
CVE-2025-8043CRITICAL9.8Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir...
CVE-2025-8038CRITICAL9.8Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ...
CVE-2025-8037CRITICAL9.1Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o...
CVE-2025-8031CRITICAL9.8The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti...
CVE-2025-8028CRITICAL9.8On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction...
CVE-2025-6523CRITICAL9.5Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t...
CVE-2025-34143CRITICAL9.3An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login...
CVE-2025-4285CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati...
CVE-2025-6187CRITICAL9.8The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf...
CVE-2025-7950CRITICAL9.8A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue i...
CVE-2025-54127CRITICAL9.8HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and be...
CVE-2025-54122CRITICAL10Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulne...
CVE-2025-54071CRITICAL9.4RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte...
CVE-2025-52362CRITICAL9.1Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and...
CVE-2025-7933CRITICAL9.8A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects...
CVE-2025-44654CRITICAL9.8In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead t...
CVE-2025-36846CRITICAL9.8An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost ...
CVE-2025-7393CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This iss...
CVE-2025-7930CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi...
CVE-2025-7929CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now