2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27282CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator ...
CVE-2025-24577CRITICAL9.8Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con...
CVE-2025-22655CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD –...
CVE-2025-3651CRITICAL9.3Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allo...
CVE-2025-29047CRITICAL9.8Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra...
CVE-2025-29046CRITICAL9.8Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitra...
CVE-2025-29045CRITICAL9.8Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_te...
CVE-2025-29044CRITICAL9.8Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via th...
CVE-2025-29041CRITICAL9.8An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t...
CVE-2025-29040CRITICAL9.8An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t...
CVE-2025-2188CRITICAL9.1There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service co...
CVE-2025-1532CRITICAL9.1Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affec...
CVE-2025-3113CRITICAL9A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database con...
CVE-2025-31340CRITICAL9.9A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Informa...
CVE-2025-0756CRITICAL9.1Overview   The product receives input from an upstream component, but it does not restrict or incorrectly restric...
CVE-2025-32433CRITICAL10Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O...
CVE-2025-3729CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen...
CVE-2025-3727CRITICAL9.8A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com...
CVE-2025-29709CRITICAL9.8SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfo...
CVE-2025-29708CRITICAL9.8SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Se...
CVE-2025-3726CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-3725CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is...
CVE-2025-3724CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function...
CVE-2025-3723CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processi...
CVE-2025-31201CRITICAL9.8This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Seq...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now