2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-44658CRITICAL9.8In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to on...
CVE-2025-44655CRITICAL9.8In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This co...
CVE-2025-7928CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som...
CVE-2025-46122CRITICAL9.1An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticat...
CVE-2025-46121CRITICAL9.8An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `...
CVE-2025-46120CRITICAL9.8An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDir...
CVE-2025-46117CRITICAL9.1An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir...
CVE-2025-7624CRITICAL9.8An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (2...
CVE-2025-6704CRITICAL9.8An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than ...
CVE-2025-7921CRITICAL9.8Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote...
CVE-2025-7343CRITICAL9.8The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbi...
CVE-2025-24937CRITICAL9File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in...
CVE-2025-24936CRITICAL9The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v...
CVE-2025-7918CRITICAL9.8WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-7916CRITICAL9.8WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remot...
CVE-2025-7915CRITICAL9.8A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function...
CVE-2025-7911CRITICAL9.8A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf ...
CVE-2025-47917CRITICAL9.8Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit...
CVE-2025-7897CRITICAL9.8A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue ...
CVE-2025-7895CRITICAL9.8A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the...
CVE-2025-7894CRITICAL9.8A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function ...
CVE-2025-7888CRITICAL9.8A vulnerability was found in TDuckCloud tduck-platform 5.1 and classified as critical. This issue affects the function U...
CVE-2025-7879CRITICAL9.8A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnera...
CVE-2025-7877CRITICAL9.8A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affec...
CVE-2025-7876CRITICAL9.8A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the fu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now