2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-53633CRITICAL9.8Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-53632CRITICAL9.1Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i....
CVE-2025-34102CRITICAL9.3A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi...
CVE-2025-34101CRITICAL9.3An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i...
CVE-2025-34100CRITICAL9.3An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man...
CVE-2025-34099CRITICAL9.3An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici...
CVE-2025-34096CRITICAL9.3A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w...
CVE-2025-34095CRITICAL9.3An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter...
CVE-2025-7411CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne...
CVE-2025-53378CRITICAL9.8A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all...
CVE-2025-53371CRITICAL9.1DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel...
CVE-2025-7410CRITICAL9.8A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno...
CVE-2025-7409CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p...
CVE-2025-47812CRITICAL10In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o...
CVE-2025-23048CRITICAL9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien...
CVE-2025-46788CRITICAL9.1Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to cond...
CVE-2025-53624CRITICAL10The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus...
CVE-2025-53620CRITICAL9.2@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the ...
CVE-2025-53546CRITICAL9.1Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm...
CVE-2025-6514CRITICAL9.6mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut...
CVE-2025-3499CRITICAL10The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086)...
CVE-2025-3498CRITICAL9.9An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 -...
CVE-2025-7220CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this...
CVE-2025-7219CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an...
CVE-2025-7218CRITICAL9.8A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now