2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-7454CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Aff...
CVE-2025-52950CRITICAL9.6A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based atta...
CVE-2025-50121CRITICAL9.5A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist...
CVE-2025-5392CRITICAL9.8The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 ...
CVE-2025-30026CRITICAL9.8The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
CVE-2025-30023CRITICAL9The communication protocol used between client and server had a flaw that could lead to an authenticated user performing...
CVE-2025-7401CRITICAL9.8The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and w...
CVE-2025-7436CRITICAL9.8A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This ...
CVE-2025-52579CRITICAL9.4Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to d...
CVE-2025-2523CRITICAL9.4The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con...
CVE-2025-53633CRITICAL9.8Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-53632CRITICAL9.1Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-34102CRITICAL9.3A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi...
CVE-2025-34101CRITICAL9.3An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i...
CVE-2025-34100CRITICAL9.3An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man...
CVE-2025-34099CRITICAL9.3An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici...
CVE-2025-34096CRITICAL9.3A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w...
CVE-2025-34095CRITICAL9.3An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter...
CVE-2025-7411CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne...
CVE-2025-53378CRITICAL9.8A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all...
CVE-2025-53371CRITICAL9.1DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel...
CVE-2025-7410CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno...
CVE-2025-7409CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p...
CVE-2025-47812CRITICAL10In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o...
CVE-2025-23048CRITICAL9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now