2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3619HIGH8.8Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potential...
CVE-2025-29710MEDIUM6.1SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
CVE-2025-29709CRITICAL9.8SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfo...
CVE-2025-29708CRITICAL9.8SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Se...
CVE-2025-28072HIGH7.5PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.
CVE-2025-26153MEDIUM5.4A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious ...
CVE-2025-3726CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-3725CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is...
CVE-2025-3724CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function...
CVE-2025-3723CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processi...
CVE-2025-32817MEDIUM6.1A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this r...
CVE-2025-29653Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-29652Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-29651Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-29650Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-29649Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-29648Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2025-31201CRITICAL9.8This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Seq...
CVE-2025-31200CRITICAL9.8A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4...
CVE-2025-39472HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Req...
CVE-2025-32872HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32871HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32870HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32869HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-32868HIGH8.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now