2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49837CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de...
CVE-2025-49836CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49835CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49834CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49833CRITICAL9.8GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in...
CVE-2025-49831CRITICAL9.8An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misco...
CVE-2025-50067CRITICAL9Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are aff...
CVE-2025-49827CRITICAL9.8Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22....
CVE-2025-41238CRITICAL9.3VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controll...
CVE-2025-41237CRITICAL9.3VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that...
CVE-2025-41236CRITICAL9.3VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A...
CVE-2025-53826CRITICAL9.8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52376CRITICAL9.8An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ...
CVE-2025-34112CRITICAL10An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr...
CVE-2025-34111CRITICAL9.8An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th...
CVE-2025-34110CRITICAL9.3A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att...
CVE-2025-34105CRITICAL10A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,...
CVE-2025-34104CRITICAL9.4An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin...
CVE-2025-34103CRITICAL9.3An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due...
CVE-2025-34068CRITICAL9.3An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5....
CVE-2025-3621CRITICAL9.6Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho...
CVE-2025-7360CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7341CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7340CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-5394CRITICAL9.8The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now