2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49710CRITICAL9.8An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir...
CVE-2025-49709CRITICAL9.8Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
CVE-2025-41663CRITICAL9.8For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman...
CVE-2025-5980CRITICAL9.8A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affect...
CVE-2025-5979CRITICAL9.8A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an u...
CVE-2025-5977CRITICAL9.8A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. This issue affects...
CVE-2025-36852CRITICAL9.4A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remo...
CVE-2025-2474CRITICAL9.8Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ...
CVE-2025-40585CRITICAL9.9A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain...
CVE-2025-30220CRITICAL9.1GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl...
CVE-2025-49507CRITICAL9.8Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affect...
CVE-2025-49455CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Wor...
CVE-2025-43698CRITICAL9.1Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level sec...
CVE-2025-40657CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40656CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40655CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-40654CRITICAL9.8A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, c...
CVE-2025-1041CRITICAL9.8An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v...
CVE-2025-5913CRITICAL9.8A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue ...
CVE-2025-5906CRITICAL9.8A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part ...
CVE-2025-42989CRITICAL9.6RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio...
CVE-2025-30184CRITICAL9.8CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
CVE-2025-49652CRITICAL9.8Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts ...
CVE-2025-49297CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.T...
CVE-2025-49296CRITICAL9.8Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now