2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-3847CRITICAL9.8A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part ...
CVE-2025-3846CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is ...
CVE-2025-3845CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner...
CVE-2025-3842CRITICAL9.8A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse...
CVE-2025-32958CRITICAL9.8Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses act...
CVE-2025-3841CRITICAL9.8A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9...
CVE-2025-28104CRITICAL9.1Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
CVE-2025-32431CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-...
CVE-2025-29660CRITICAL9.8A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789....
CVE-2025-29659CRITICAL9.8Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi...
CVE-2025-29287CRITICAL9.8An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary cod...
CVE-2025-0632CRITICAL9.2Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attack...
CVE-2025-43973CRITICAL9.8An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds ...
CVE-2025-43964CRITICAL9.8In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum...
CVE-2025-43963CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col an...
CVE-2025-43962CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing...
CVE-2025-43961CRITICAL9.1In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
CVE-2025-43955CRITICAL9.8TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.
CVE-2025-3830CRITICAL9.8A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerabi...
CVE-2025-3829CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is...
CVE-2025-3828CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s...
CVE-2025-3827CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil...
CVE-2025-43928CRITICAL9.8In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../...
CVE-2025-3819CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-3807CRITICAL9.8A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now