2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-29287CRITICAL9.8An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary cod...
CVE-2025-0632CRITICAL9.2Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attack...
CVE-2025-43973CRITICAL9.8An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds ...
CVE-2025-43964CRITICAL9.8In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum...
CVE-2025-43963CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col an...
CVE-2025-43962CRITICAL9.1In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing...
CVE-2025-43961CRITICAL9.1In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
CVE-2025-3830CRITICAL9.8A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerabi...
CVE-2025-3829CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is...
CVE-2025-3828CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s...
CVE-2025-3827CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil...
CVE-2025-43928CRITICAL9.8In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../...
CVE-2025-3819CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi...
CVE-2025-3807CRITICAL9.8A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload ...
CVE-2025-3800CRITICAL9.8A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown funct...
CVE-2025-3799CRITICAL9.8A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app...
CVE-2025-1093CRITICAL9.8The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat...
CVE-2025-3278CRITICAL9.8The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0....
CVE-2025-29058CRITICAL9.8An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-28197CRITICAL9.1Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
CVE-2025-28242CRITICAL9.8Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session ...
CVE-2025-28238CRITICAL9.8Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers t...
CVE-2025-28236CRITICAL9.8Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerabili...
CVE-2025-28233CRITICAL9.1Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Ve...
CVE-2025-28231CRITICAL9.1Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary comma...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now