2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4483CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by...
CVE-2025-4482CRITICAL9.8A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by th...
CVE-2025-4481CRITICAL9.8A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This...
CVE-2025-46192CRITICAL9.8SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the o...
CVE-2025-46191CRITICAL9.8Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthen...
CVE-2025-46190CRITICAL9.8SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the ...
CVE-2025-46193CRITICAL9.8SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in...
CVE-2025-46189CRITICAL9.8SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php vi...
CVE-2025-46188CRITICAL9.8SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
CVE-2025-45513CRITICAL9.8Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
CVE-2025-28200CRITICAL9.8Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits o...
CVE-2025-45887CRITICAL9.1Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
CVE-2025-45885CRITICAL9.8PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Att...
CVE-2025-1087CRITICAL9.3Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to exe...
CVE-2025-4403CRITICAL9.8The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a...
CVE-2025-4468CRITICAL9.8A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This iss...
CVE-2025-4467CRITICAL9.8A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been declared as critical. This ...
CVE-2025-3605CRITICAL9.8The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2025-2253CRITICAL9.8The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and inclu...
CVE-2025-4466CRITICAL9.8A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an...
CVE-2025-4465CRITICAL9.8A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this issue i...
CVE-2025-4464CRITICAL9.8A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this vu...
CVE-2025-3463CRITICAL9.4"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici...
CVE-2025-4463CRITICAL9.8A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. Affected is an u...
CVE-2025-47737CRITICAL9.8lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now