2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-7398CRITICAL9.1Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and...
CVE-2025-6391CRITICAL9.1Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withd...
CVE-2025-7757CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is...
CVE-2025-7753CRITICAL9.8A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th...
CVE-2025-7752CRITICAL9.8A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by...
CVE-2025-7751CRITICAL9.8A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect...
CVE-2025-53964CRITICAL9.6GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a cr...
CVE-2025-23266CRITICAL9NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher...
CVE-2025-7750CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff...
CVE-2025-54068CRITICAL9.8Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth...
CVE-2025-50240CRITICAL9.8nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR...
CVE-2025-7749CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0...
CVE-2025-53644CRITICAL9.8OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s...
CVE-2025-53867CRITICAL9.8Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
CVE-2025-52046CRITICAL9.8Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio...
CVE-2025-25257CRITICAL9.8An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi...
CVE-2025-53928CRITICAL9.8MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ...
CVE-2025-51630CRITICAL9.8TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi...
CVE-2025-7712CRITICAL9.1The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...
CVE-2025-5396CRITICAL9.8The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0...
CVE-2025-34132CRITICAL9.3A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_...
CVE-2025-34127CRITICAL9.3A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag...
CVE-2025-34125CRITICAL9.3An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D...
CVE-2025-34121CRITICAL9.3An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc...
CVE-2025-34117CRITICAL9.3A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now