2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4248CRITICAL9.8A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by th...
CVE-2025-4242CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vul...
CVE-2025-4241CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Af...
CVE-2025-4240CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown proc...
CVE-2025-4239CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow...
CVE-2025-4238CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of...
CVE-2025-4237CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f...
CVE-2025-4236CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a...
CVE-2025-4226CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This aff...
CVE-2025-3918CRITICAL9.8The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg...
CVE-2025-4214CRITICAL9.8A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue af...
CVE-2025-4213CRITICAL9.8A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulner...
CVE-2025-45800CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the...
CVE-2025-44877CRITICAL9.8Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via...
CVE-2025-44872CRITICAL9.8Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via...
CVE-2025-44868CRITICAL9.8Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm....
CVE-2025-3927CRITICAL9.8Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t...
CVE-2025-2421CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Inj...
CVE-2025-2812CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics...
CVE-2025-3709CRITICAL9.8Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attacker...
CVE-2025-3708CRITICAL9.8Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remot...
CVE-2025-3746CRITICAL9.8The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions...
CVE-2025-4195CRITICAL9.8A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerabilit...
CVE-2025-4193CRITICAL9.8A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this ...
CVE-2025-4192CRITICAL9.8A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This aff...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now