2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4631CRITICAL9.8The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt...
CVE-2025-4607CRITICAL9.8The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
CVE-2025-5370CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unk...
CVE-2025-5369CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected i...
CVE-2025-5367CRITICAL9.8A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulne...
CVE-2025-5365CRITICAL9.8A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This a...
CVE-2025-5364CRITICAL9.8A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-5363CRITICAL9.8A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected b...
CVE-2025-5362CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte...
CVE-2025-5361CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Th...
CVE-2025-5360CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability ...
CVE-2025-48949CRITICAL9.8Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulner...
CVE-2025-5359CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects a...
CVE-2025-48938CRITICAL9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been id...
CVE-2025-5358CRITICAL9.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec...
CVE-2025-5357CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability ...
CVE-2025-5356CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi...
CVE-2025-2500CRITICAL9.1A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an...
CVE-2025-48865CRITICAL9.1Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl...
CVE-2025-48481CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated ...
CVE-2025-47952CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a...
CVE-2025-48757CRITICAL9.3An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers...
CVE-2025-44619CRITICAL9.1Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attacker...
CVE-2025-46352CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string i...
CVE-2025-41438CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to ch...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now