2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-34110CRITICAL9.3A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att...
CVE-2025-34105CRITICAL10A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,...
CVE-2025-34104CRITICAL9.4An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin...
CVE-2025-34103CRITICAL9.3An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due...
CVE-2025-34068CRITICAL9.3An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5....
CVE-2025-3621CRITICAL9.6Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho...
CVE-2025-7360CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7341CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-7340CRITICAL9.8The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab...
CVE-2025-5394CRITICAL9.8The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ...
CVE-2025-5393CRITICAL9.1The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion...
CVE-2025-53890CRITICAL9.8pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoa...
CVE-2025-53835CRITICAL9XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-53833CRITICAL10LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior ...
CVE-2025-53825CRITICAL9.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo...
CVE-2025-53639CRITICAL9.8MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certai...
CVE-2025-53101CRITICAL9.8ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1....
CVE-2025-7627CRITICAL9.8A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classifi...
CVE-2025-53014CRITICAL9.8ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0...
CVE-2025-7612CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects...
CVE-2025-7611CRITICAL9.8A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an ...
CVE-2025-50756CRITICAL9.8Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newp...
CVE-2025-7610CRITICAL9.8A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this i...
CVE-2025-7609CRITICAL9.8A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vu...
CVE-2025-7608CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now