2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-31927CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:...
CVE-2025-31918CRITICAL9.8Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro...
CVE-2025-31916CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium ...
CVE-2025-31914CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel...
CVE-2025-31631CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue...
CVE-2025-31430CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The...
CVE-2025-31423CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec...
CVE-2025-31397CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke...
CVE-2025-31069CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti...
CVE-2025-31056CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar...
CVE-2025-31049CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ...
CVE-2025-3895CRITICAL9.1Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ...
CVE-2025-5099CRITICAL9.8An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c...
CVE-2025-5098CRITICAL9.1PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's...
CVE-2025-48373CRITICAL9.1Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ...
CVE-2025-30171CRITICAL9System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator ...
CVE-2025-2410CRITICAL9.1Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session...
CVE-2025-2409CRITICAL9.1File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c...
CVE-2025-43596CRITICAL9.8An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands ...
CVE-2025-5081CRITICAL9.8A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerab...
CVE-2025-5079CRITICAL9.8A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown f...
CVE-2025-32814CRITICAL9.8An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
CVE-2025-5078CRITICAL9.8A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the ...
CVE-2025-5077CRITICAL9.8A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an u...
CVE-2025-5076CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now