2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-53888CRITICAL9.8RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `a...
CVE-2025-46001CRITICAL9.8An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to ...
CVE-2025-7444CRITICAL9.8The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0...
CVE-2025-26855CRITICAL9.8A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL c...
CVE-2025-26854CRITICAL9.8A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQ...
CVE-2025-7643CRITICAL9.1The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-6222CRITICAL9.8The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres...
CVE-2025-6185CRITICAL9.3Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an atta...
CVE-2025-7765CRITICAL9.8A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi...
CVE-2025-7764CRITICAL9.8A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i...
CVE-2025-7398CRITICAL9.1Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and...
CVE-2025-6391CRITICAL9.1Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withd...
CVE-2025-7757CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is...
CVE-2025-7753CRITICAL9.8A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th...
CVE-2025-7752CRITICAL9.8A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by...
CVE-2025-7751CRITICAL9.8A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect...
CVE-2025-53964CRITICAL9.6GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a cr...
CVE-2025-23266CRITICAL9NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher...
CVE-2025-7750CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff...
CVE-2025-54068CRITICAL9.8Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth...
CVE-2025-50240CRITICAL9.8nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR...
CVE-2025-7749CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0...
CVE-2025-53644CRITICAL9.8OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s...
CVE-2025-53867CRITICAL9.8Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
CVE-2025-52046CRITICAL9.8Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now