2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32403CRITICAL9.8An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ...
CVE-2025-32401CRITICAL9.8An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d...
CVE-2025-3844CRITICAL9.8The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to...
CVE-2025-0855CRITICAL9.8The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via ...
CVE-2025-47419CRITICAL10Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. ...
CVE-2025-46572CRITICAL9.3passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in ...
CVE-2025-44899CRITICAL9.8There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the we...
CVE-2025-44073CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-46816CRITICAL9.4goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a...
CVE-2025-25014CRITICAL9.8A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine lea...
CVE-2025-4041CRITICAL9.3In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh serve...
CVE-2025-4368CRITICAL9.8A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetR...
CVE-2025-4363CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue ...
CVE-2025-45492CRITICAL9.8Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.
CVE-2025-45491CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun...
CVE-2025-45490CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun...
CVE-2025-45489CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun...
CVE-2025-45488CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun...
CVE-2025-45487CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection fu...
CVE-2025-4362CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. This vulnerability affects u...
CVE-2025-4361CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. This affects ...
CVE-2025-4360CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by...
CVE-2025-4359CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerabili...
CVE-2025-4358CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is a...
CVE-2025-4357CRITICAL9.8A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now