2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4300CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unkn...
CVE-2025-4299CRITICAL9.8A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the funct...
CVE-2025-4298CRITICAL9.8A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affect...
CVE-2025-4297CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affect...
CVE-2025-4291CRITICAL9.8A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. ...
CVE-2025-4290CRITICAL9.8A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk...
CVE-2025-44074CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
CVE-2025-44072CRITICAL9.8SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
CVE-2025-44071CRITICAL9.8SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This ...
CVE-2025-4289CRITICAL9.8A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t...
CVE-2025-4288CRITICAL9.8A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com...
CVE-2025-46726CRITICAL9.1Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM applicati...
CVE-2025-45616CRITICAL9.8Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a craft...
CVE-2025-45615CRITICAL9.8Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights...
CVE-2025-45612CRITICAL9.8Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
CVE-2025-45611CRITICAL9.8Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via ...
CVE-2025-45607CRITICAL9.8An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.
CVE-2025-1909CRITICAL9.8The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,...
CVE-2025-4318CRITICAL9The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input valida...
CVE-2025-4283CRITICAL9.8A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue...
CVE-2025-43852CRITICAL9.8Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu...
CVE-2025-43851CRITICAL9.8Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu...
CVE-2025-43850CRITICAL9.8Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu...
CVE-2025-43849CRITICAL9.8Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vu...
CVE-2025-4052CRITICAL9.8Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now