2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-7831CRITICAL9.8A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unkno...
CVE-2025-7830CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i...
CVE-2025-7829CRITICAL9.8A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi...
CVE-2025-7824CRITICAL9.8A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing...
CVE-2025-7823CRITICAL9.8A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code...
CVE-2025-29757CRITICAL9.4An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous at...
CVE-2025-7697CRITICAL9.8The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable...
CVE-2025-7696CRITICAL9.8The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to ...
CVE-2025-7395CRITICAL9.2A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VA...
CVE-2025-7394CRITICAL9.8In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to ...
CVE-2025-7814CRITICAL9.8A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability af...
CVE-2025-54309CRITICAL9.8CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and...
CVE-2025-7783CRITICAL9.4Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability...
CVE-2025-53762CRITICAL9.9Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a networ...
CVE-2025-47158CRITICAL9Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov...
CVE-2025-53888CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `a...
CVE-2025-46001CRITICAL9.8An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to ...
CVE-2025-7444CRITICAL9.8The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0...
CVE-2025-26855CRITICAL9.8A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL c...
CVE-2025-26854CRITICAL9.8A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQ...
CVE-2025-7643CRITICAL9.1The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-6222CRITICAL9.8The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres...
CVE-2025-6185CRITICAL9.3Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an atta...
CVE-2025-7765CRITICAL9.8A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi...
CVE-2025-7764CRITICAL9.8A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now